--- title: "Phillip Wylie -- Pen Testing from Somebody who Knows about Pen Testing" url: https://appsecpodcast.com/phillip-wylie-pen-testing-from-somebody-who-knows-about-pen-testing/ date: 2024-09-17 duration_seconds: 3128 season: 11 episode: 22 guests: ["Phillip Wylie"] topics: ["Security Testing", "Vulnerabilities and Exploits", "Careers in AppSec"] audio: https://www.buzzsprout.com/1730684/episodes/15763999-phillip-wylie-pen-testing-from-somebody-who-knows-about-pen-testing.mp3 video: https://www.youtube.com/watch?v=OVt55RXQ_r4 transcript: true --- # Phillip Wylie -- Pen Testing from Somebody who Knows about Pen Testing *September 17, 2024 · 52 min · Season 11, episode 22* with [Phillip Wylie](https://appsecpodcast.com/guests/phillip-wylie/) on [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Vulnerabilities and Exploits](https://appsecpodcast.com/topics/vulnerabilities/), [Careers in AppSec](https://appsecpodcast.com/topics/careers/) [Audio](https://www.buzzsprout.com/1730684/episodes/15763999-phillip-wylie-pen-testing-from-somebody-who-knows-about-pen-testing.mp3) · [Video](https://www.youtube.com/watch?v=OVt55RXQ_r4) ## Show notes Philip Wiley shares his unique journey from professional wrestling to being a renowned pen tester. We define pen testing and the role of social engineering in ethical hacking. We talk tools of the trade, share a favorite web app pentest hack and offer good advice on starting a career in cybersecurity. Philip shares some insights from his book, ‘The Pentester Blueprint: Starting a Career as an Ethical Hacker. ’ And we discuss the impact of AI on pen testing and where this field is headed in the next few years. Our guest in this episode is Phillip Wiley. We explore the definition of pentesting, its relationship with red team activities, and the role of social engineering in ethical hacking. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Phillip Wylie: → [Phillipwylie](https://www.linkedin.com/in/phillipwylie/) → [Ranakhalil1](https://www.linkedin.com/in/ranakhalil1) Mentioned in this episode: → [The Pentester Blueprint: Starting a Career as an Ethical Hacker](https://www.wiley.com/en-us/The+Pentester+BluePrint%3A+Starting+a+Career+as+an+Ethical+Hacker-p-9781119684374) → [The Web Application Hacker's Handbook](https://www.wiley.com/en-us/The+Web+Application+Hacker's+Handbook%3A+Finding+and+Exploiting+Security+Flaws%2C+2nd+Edition-p-9781118175248) → [The Hacker Maker](https://thehackermaker.com/) → [The Phillip Wylie Show](https://phillipwylieshow.com/) → [@PhillipWylie](https://x.com/PhillipWylie) → [Phillipwylie](https://www.linkedin.com/in/phillipwylie/) → [The Web Application Hacker](https://www.wiley.com/en-us/The+Web+Application+Hacker) → [The Pentester BluePrint: Starting A Career As An Ethical Hacker P 9781119684305](https://www.wiley.com/en-us/The+Pentester+BluePrint:+Starting+a+Career+as+an+Ethical+Hacker-p-9781119684305) → [Burp Suite](https://portswigger.net/burp) → [OWASP ZAP](https://www.zaproxy.org) → [Metasploit](https://www.metasploit.com/) → [Nessus](https://www.tenable.com/products/nessus) → [sqlmap](https://sqlmap.org/) → [Kali Linux](https://www.kali.org/) → [Bugcrowd](https://www.bugcrowd.com/) → [SANS Institute](https://www.sans.org/) → [Ranakhalil1](https://www.linkedin.com/in/ranakhalil1) → [PCI DSS](https://www.pcisecuritystandards.org/standards/pci-dss/) Chapters: 00:00 Meet Phillip Wylie: Pen Testing from Somebody who Knows about Pen Testing 02:33 Right. Oh, the typical story. No, unfortunately, I wish it was 06:19 So one, one last wrestling question. This is quickly becoming the 09:31 I gotta imagine that there's a certain amount of improv though 11:19 Good decision there. So Phillip, how about security 15:13 Mm-hmm. So pen testing, I think, is the, is the primary 19:30 Yeah, that's a good, that's a good, good way to summarize 22:45 You mentioned SQL injection. I'm always curious to understand from somebody 24:12 Okay. So it's not something that's, uh, yeah, that's interesting that 27:03 I wanted to circle back on, you mentioned social engineering and 29:18 With payloads, like I said. Yeah. So if we think about 32:52 Let's shift a little bit. Uh, I know that you've done 35:47 We want to just mention and hear a little bit more 38:36 Yeah, that's really cool. And I want to, um, I want 39:31 I, and the pet peeve I have is Talk to a 46:46 Yeah. How is, um, another just off the top of my 50:11 Phillip, I want to just, I know you do podcasts and ## Transcript *9,947 words · assemblyai* **0:00 Chris Romeo:** Our guest in this episode is Phillip Wiley. We explore the definition of pentesting, its relationship with red team activities, and the role of social engineering in ethical hacking. We discuss essential tools of the trade, and we get to hear an all-time favorite web app pentest hack from Phillip. Phillip also offers advice for starting a career in pentesting, including some insights from the book that he wrote, The Pentester Blueprint: Starting a Career as an Ethical Hacker. Towards the end, we examine the impact of AI on pentesting, and we think about where the field is headed in the next 5 to 10 years. **0:35 Phillip Wylie:** The Application Security Podcast is brought to you by Security Journey. Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term measurable results. Learn more at securityjourney.com. **0:49 Robert Hurlbut:** Hey folks, welcome to another episode of the Application Security Podcast. **1:02 Phillip Wylie:** I'm Robert Hurlbut. **1:03 Robert Hurlbut:** I'm a principal application security architect at Acquia, as well as threat modeling lead. And I'm joined by my co-host and longtime friend, Chris Romeo. Hey, Chris. Hey, Robert. **1:14 Chris Romeo:** Chris Romeo, CEO of DaVinci, and, uh, excited to dive into the world of pen testing today. Something that, uh, we don't talk about very often. **1:26 Robert Hurlbut:** No, not very many times. I was thinking about, uh, some of our previous episodes over the years, and it's been a number of years now, and, uh, we haven't really covered this, uh, too often. So, uh, great to dive in and take a look. And our guest today is Phillip Wiley. Uh, Phillip, welcome. **1:43 Chris Romeo:** Thanks. Great to be here. **1:46 Phillip Wylie:** And it was, it was nice meeting you during DEF CON. **1:48 Robert Hurlbut:** Yeah, definitely. Uh, really, uh, I've followed your work for a while. I've seen your name certainly float around and different things you're doing. And so it was a great opportunity to meet you. As you mentioned, we had breakfast there, and then we also got to walk around a little bit and see what was going on in the new venue there for DEF CON this year, which was actually very cool. I really enjoyed it. I was glad that they did that. It worked out well, I think. **2:15 Chris Romeo:** So this was not the story that I thought you were gonna tell about meeting at DEF CON. I was like, you know, we were, it was 3:00 AM, We hadn't, uh, slept for 3 days and, uh, we were, we were hacking something that cannot be described in the building. And then we jumped in the pool, you know? **2:33 Robert Hurlbut:** Right. Oh, the typical story. No, unfortunately, I wish it was a, you know, maybe more exciting. Yeah. But no, it wasn't quite like that. But, uh, yeah. So again, we're glad to have you here. Uh, as we typically do in our podcast, we start out, uh, with our guest, uh, giving us, uh, your security origin story. So I want to start there. And, uh, if you could, uh, let us know, how did you get into this, uh, great world of security? **3:00 Phillip Wylie:** Sure. Do you want the scenic route or the short, short story? **3:05 Robert Hurlbut:** Whatever works. You tell us. Uh, yeah, let's, let's go the scenic route. I'd love to hear it. **3:11 Phillip Wylie:** Okay. Yeah. Some people like to hear, hear the, the story before I even got into security. So when I graduated high school, I had no idea of what I wanted to do for a living. And I was a powerlifter and my friend said, hey, you should be a pro wrestler. So I went to wrestling school and wrestled for a couple years. And, and during that time I actually wrestled a 750-pound bear. **3:31 Chris Romeo:** Wow. So much I want to unpack here. **3:37 Phillip Wylie:** I don't even want to talk about security now. **3:40 Chris Romeo:** So what is wrestling school? What is wrestling school? I didn't know this existed. **3:43 Phillip Wylie:** Oh yeah, there's all sorts. Back then it wasn't as widely available, but I went into a wrestling school in downtown Dallas. It was in Doug's Gym, uh, and it was ran by General Skandar Akbar, which was the gentleman's wrestling name that, that ran the school, which was pretty, pretty big back then. He had managed like Kamala at one time and, and some others. His, his organization he referred to as Devastation Incorporated. **4:08 Chris Romeo:** Yeah. So wrestling school. So it's like a, I'm imagining it's a gym and they've got a ring and they're teaching you different techniques and stuff so that you don't get hurt ultimately. **4:25 Phillip Wylie:** Yes. To teach you how to wrestle because you have to learn how to pull punches. And, and the thing was when I went into it, I had no idea what, what to expect because Back then it was before they admitted that it wasn't real. And so I thought, they're not gonna let any, I would think, was thinking they're not gonna let just anyone off the street come in and show them that it's not real. Because if someone wanted to find out that time if it was real or not, all they had to do is send someone to wrestling school and they could find out pretty quickly. And I thought that, you know, they wouldn't let you in on the secret right away, but right away they did. I was kind of, uh, going in kind of wondering how it was gonna be, if you had to kind of get really beat up and go through all this torturous, uh, initiation. But it really wasn't that way. You went in, they showed you how it was, how to protect yourself when you fall. And, and it, it was pretty interesting. So during that time I wrestled Mick Foley. He was wrestling in Dallas as Cactus Jack. Uh, the first time I wrestled, the first night I wrestled, I wrestled the Rock and Roll Express, or actually the Midnight Express and the Road Warriors the very first night I wrestled. Yeah. **5:34 Chris Romeo:** Holy cow, man. And that's, oh, that's so crazy that, uh, I'm guessing you always lost though. **5:41 Phillip Wylie:** I remember the script. Yes. Yeah. They, we were what they referred to as job boys or jobbers. So basically you went and lost all the time. I went to wrestling school with The Undertaker and it was the same thing with him, even though this guy was gigantic. He had to go through the same thing, paying your dues. The only people you really saw that didn't pay their dues were somehow related to people in the red— the wrestling industry, just like Dwayne Johnson, The Rock. He had family there, so it wasn't like he had to go and getting, get it, you know, get beat up and all that all the time. And that's usually the case. If you see someone starting out winning or not having to lose all the time, then they were related to someone somehow or another. **6:17 Robert Hurlbut:** Hmm. **6:19 Chris Romeo:** And so one, one last wrestling question. This is quickly becoming the wrestling podcast, but that's okay because I mean, come on, we grew up with wrestling. Like it was like on TV. I remember when it used to be on TBS and there was the, um, Iron Sheik and I don't remember who all the people were there, but it was a big part of probably all of our childhoods. Like as we were watching these, these things happen. So, uh, what was the craziest thing that happened to you? In the ring? **6:45 Phillip Wylie:** Craziest thing I say, probably the, one of the scariest things is I wrestled the Samoan SWAT team. These were a couple guys that are cousins to Dwayne Johnson. It was in a tag team match. And most people, most people were pretty decent at pulling their punches. But the thing you have to consider about Samoans is they're all naturally large people. I mean, even the women are like 6 foot tall, 200-something pounds. So these 2 guys I was wrestling were probably about 350 and 6'3, 6'2 or something like that. Just really huge guys. And it was a tag team match. And I kind of noticed how my opponent, my tag team partner got thrown in the ropes and I saw like red hair flowing down, like where they'd had ahold of his hair and threw him in the ropes. And then wasn't too concerned until I got in there. They threw me in the corner and then just hit me in the jaw. And I mean, you know, this was like, Full force, a normal, you know, 200, 220-pound man would hit you with that kind of force, but this was, they're pulling punches. So when they threw me in the corner and hit me in the jaw, it's like, man, what did he do to piss them off? And so, uh, as the match progressed, I got suplexed off the top ropes and he jumped off on me. And so there's a couple of ways they do that. Typically when people jump off the ropes, they fully You know, they, they break their fall. They don't really land full force on you. The way they did it is you start raising up. I didn't know that part. So he jumped off without trying to break his fall, landed on me full force, 200 and, I mean, 350 pounds off of, you know, the ropes were about 5 foot or so, jumping off this 5-foot surface and landing on me. And so the fall wasn't broken and knocked the wind out of me. **8:33 Robert Hurlbut:** Yeah. **8:34 Phillip Wylie:** So we got tagged out. The referee's trying to get me up so they can clear the ring out for the next match. I was, I'd lost my breath, was winded, couldn't catch my breath. So I was sitting there trying to catch my breath, finally caught it. And when I was walking out of the ring, I was spitting up blood. **8:50 Chris Romeo:** Oh man. **8:51 Phillip Wylie:** So, so that was scary. I kind of got off lucky because most people ended up with like whiplash or concussions that wrestled these guys. Unfortunately, I came away with Mine wasn't that bad. I think the, the spitting of blood, maybe I bit my cheek or something. I don't think it was anything too serious, but it was, yeah, it was a, a scary experience. I mean. **9:13 Chris Romeo:** So did they just, did they end the match like knowing you were injured or was it supposed to end right there? **9:20 Phillip Wylie:** It was, it was planned. That was their finishing move. That was planned, the, the planned ending. And so just, it worked out pretty well cuz otherwise. I would've been laying on the mat for a while if the, if the, the match wasn't over. **9:30 Chris Romeo:** I gotta imagine that there's a certain amount of improv though. Yes. When you're in the ring, like if something, cuz like it's the show must go on, right? Like you can't just, yeah, stop. Okay, cut. Let's take 2. Everybody start again. Back to the dressing rooms. We're coming out again. Right? Like, yeah, you have to kind of flow and put on a good show. And so I'm imagining like there, there are times where Things don't go as they're supposed to and you just have to improv. **9:56 Phillip Wylie:** Yes. And it, there's a lot of improv to it to begin with, cuz a lot of people think that you practice beforehand, but wrestlers travel so much they don't have that opportunity to get together and try a couple times, just a practice run of the match. It's like you're there in a locker room, you kind of discuss the finishing move, maybe some special moves that they have. Uh, because, you know, mo— a lot of it's pretty typical. A lot of the falls are the same. So if they do like a hip toss or a body slam, it's all pretty much like a frontward roll, you know, kind of a flip. You just, so the falls, a lot of the falls are, are the same. And so, like I said, they, it's not, it's, it's only planned what the ending is gonna be, how long the match will be. And some wrestlers will have things where they'll tell you, if I squeeze your wrist twice, you reverse the move. **10:47 Robert Hurlbut:** Mm-hmm. **10:47 Phillip Wylie:** So, so the matches I got lucky to do anything in and just totally, instead of get totally slaughtered, my opponent would, would, you know, squeeze my wrist a couple times and then I would reverse the hold on them or whatever. So. **10:58 Chris Romeo:** Fascinating. **11:01 Robert Hurlbut:** Yes. **11:03 Chris Romeo:** Wow. Okay. We should talk about security, application security as well here. **11:06 Phillip Wylie:** Yeah. **11:06 Chris Romeo:** I mean, that's, uh, I could probably keep asking questions here and we could fill a whole hour just on your experiences in the world of wrestling. That's, that's really cool. That's really neat. I'm glad you went the scenic route, Robert. That was a good, good, uh, I know, right? **11:18 Robert Hurlbut:** Who knew? **11:19 Chris Romeo:** Good decision there. So Phillip, how about security? How, how do you, how, so here's the question. How do you transition from professional wrestling to security? **11:26 Phillip Wylie:** Well, so I, so I got married in '89. No, I was actually got married in '88 and needed to get a, had a better career or something with insurance because I was wrestling maybe once a week if I was lucky. My full-time job was working as a bouncer and that's where I wrestled the bear. So I was, and so I needed a job with insurance and benefits. And so I'd worked several different jobs that did retail sales, construction. I hated construction, roofed houses, put up fences, framed houses, worked in restaurants and all this. And so finally one day I was watching television and saw an advertisement for the American Trades Institute, which was a trade school. And one of the things they taught was AutoCAD. So I liked drawing when I was a kid and I took some drafting classes in high school. And ultimately I wanted to go to CAD school because I had designed some exercise equipment and I thought, yeah, this would be a cool job to get into exercise equipment design. And so once I went through CAD school, found out the money was really not in designing exercise equipment. There were very few jobs in that area and I followed the money. And so after working in, uh, the CAD industry for a while. I found out about sysadmin work, found out it paid more. I had more of a knack for it when I was going through, through the trade school. I probably had some of the worst computer skills out of my class because I didn't have exposure to computers. The only thing I had experience with, we had a computer at home that my father-in-law gave us to use and play like Prodigy games. And that was it. And so I really didn't know how to use a computer. So. Going through class, classes, learning how to use a computer, getting out into the, the field and then kind of figuring things out. Most of the places I worked at had Novell network, NetWare networks. And so one place I worked at, we'd got Windows 95 and the, the onsite IT person couldn't figure out how to get Windows 95 to print through a Novell NetWare print server. So I was able to figure that out and taught myself how to build computers. Took a Novell NetWare CNE certification course, which was like 90 days. After I completed that, I got my first job. Uh, it was during the dot-com boom. So I easily, I only interviewed for like one IT job and I got it. And it was basically building NetWare servers and upgrading from NetWare 3.12 to 4.11 and upgrading from Windows to Windows 95. And so that's kind of how I got my start, did sysadmin, uh, roles for a little over 6 years and moved into security in January of 2000, 2004. So the first year, year and a half I spent doing network security, uh, did some vulnerability scanning, managed firewalls, intrusion detection systems. And then the company where I worked at, we hired a new CISO. He had a more modern idea of the way things were done in security, and he put us in different silos. And fortunately, I got put in application security. So I spent from about September 2004, 2005 to March of 2012 working application security. I got laid off from my job, applied for a role consulting at Verizon as a penetration tester, and that's kind of where I got my start there, but. Uh, a big part of my career was spent in application security. Application security is where I learned about pen testing, and pen testing is the one role I've been in the longest in, uh, cybersecurity. So I've been in on the offensive side for a little over 12 years. Previous to that, the longest time, my longest role in security was application security from like September 2005 to March 2012. **15:12 Chris Romeo:** Mm-hmm. So pen testing, I think, is the, is the primary thing that we want to explore here with some, some different angles on it perhaps. But I think it would be beneficial to define pen testing because this is one of those terms that it's, everybody thinks or seems to think that they know exactly what it is and that we all agree. But I think there is some, some differences of, of interpretation, I guess, of that definition. So when you think penetration testing, what's your definition and how does red teaming, blue teaming, any other teaming kind of fit into that and intersect? **15:51 Phillip Wylie:** Sure. So penetration testing is assessing the security from a threat actor perspective. And some of the misconceptions are, get, there's a lot of confusion between red teaming and pen testing. With pen testing, you're going in using different, uh, type of, type of hacker techniques. To assess the security of a system. So you're trying, you know, the most common things is hacking into it computer-wise. You can use social engineering to try to hack the human element of it. Uh, you can even get into physical building security, trying to break into buildings. And, you know, originally pen testing was more full scope. You had all things typically in, in the rules of engagement or in scope for the pen test, you know. Uh, social engineering was used a lot more often. Actual phishing with, without, you know, not the, the tools where you send out the monthly test to see if someone clicks on something, but you really don't know what happens if they click on a payload. Uh, so it was kind of really more full scope. PCI really changed the way things were being done. Scopes were so narrow, only certain, you know, certain environments would be left out, certain techniques were left out. So it got down to where. You know, pen testing was really more towards the computer hacking side of things. Uh, you know, one of the things that's described too is you're using ethical hacking skills within a penetration test. Sometimes people call it ethical hacking, but that is part of the things that you use in a penetration test. So you can do ethical hacking without necessarily being a pen test. Uh, a lot of the confusion with the red teaming comes because people think that pen testing is red teaming and they get confused. So if you hear someone that creates course content or tries to create a course or books on, uh, red teaming or like on pen testing that don't know any better. They think it's more like red teaming. You're trying to go undetected and all this. And that's not the case. Pen tests are sometimes referred to as a time box test. So you got a limited amount of time. Everyone really needs to know in an organization what's going on in case something breaks, can be fixed. That way they can tell the difference between malicious and legit offensive security activities going on. So that needs to be reported. With the red team operation, the control group is the only one that knows, typically the CISO, maybe a few managers, because you're not really going to tip off the blue team because you're also testing the response of the blue team, not just the technology. Whereas in a pen test, it's more focused on technology unless you're doing social engineering. And it's also testing like the incident response plan with the red team operation. So you're testing to see if people are following that. If a company has incident response, are they following it? One of the best outcomes that I've really heard of from a red team operation was this company had an incident response company on retainer in case they had an incident. A red team operation was going on. The blue team detected it, called this company. They came in. To investigate and try to, uh, stop the attack and, and so forth. And they'd call the CISO up and say, hey, we've got a breach going on. We've got the incident response team in. And that's kind of the way you want it to happen. That way they detected it. Sometimes these EDRs, different endpoints aren't tuned well enough and just the noise of everything drowns out legitimate malicious activity. So this is the kind of outcome that you want to see. One of the best descriptions I heard for red teaming was by the founder of Dallas Hackers Association that goes under the handle Wirefall. His description is the red team tests the blue team. **19:29 Chris Romeo:** Yeah, that's a good, that's a good, good way to summarize it in, in such a close, you know, such a tight definition. I'm always curious when people do pen testing and red teaming. As to understand, like, what are some of the best stories of things that you've accomplished in that? Like, what were some of the coolest things? And I know sometimes you end up doing, you know, spending 15 minutes and, and being able to get into somebody's system. And it's not as, it's not as cool as in the movies, but like, yeah. Can you share one or two examples of some of the cool things that you've, you've seen and maybe some of the most unique, uh, attack vectors you've been able to exploit? **20:13 Phillip Wylie:** One of my favorite all-time hacks, and actually my license plate kind of is SQL injection related. Uh, but at any rate, uh, one of my favorite all-time hacks is I was actually out of town up in Mississippi visiting family. My mom was actually in, was in the hospital there. So I was visiting and then one night working from the hotel, uh, I was doing an application pen test and I was doing my, my Burp scan, Burp Suite scans, and found that one of the, that the application may be vulnerable to a SQL injection vulnerability. So I was doing manual validation with, or actually validation with, with SQLMap. And sure enough, it was vulnerable to SQL injection. They had XP command shell enabled, enabled, and I was able to get command line access to the system, dump the password hash and crack it with John the Ripper in less than than 30 seconds. This was back in 2014. So Hashcat wasn't as popular then. Maybe it was just coming around, but I was able to, to crack the password hash in like 30 seconds or less. And the password was password, all lowercase and the number 1. **21:20 Chris Romeo:** Yeah. **21:22 Phillip Wylie:** They had XP command shell running, which was, which allowed it and open to the internet. And the most ridiculous thing was, and this is one of the things I really preach to people on pen tests, you know, pen tests are worthless if you don't do the remediation. You can't just check the box each year and expect to be secure. You're only going to improve your security posture if you act on the results of that pen test. And this company come up and say, yeah, we were aware of that vulnerability, but we're going to file a risk acceptance because it's a development server. **21:51 Chris Romeo:** I wish I knew who that was. Don't tell me because yeah. Just so I can make sure. **21:57 Phillip Wylie:** Actually, I don't even remember who it is now, but, but so the dev server was exposed, right? **22:04 Robert Hurlbut:** So it was, yes, it was. Yeah. So, but it's just the dev server. **22:07 Phillip Wylie:** Yeah. **22:08 Robert Hurlbut:** It's all good. It's all good. **22:09 Chris Romeo:** Yeah. **22:10 Phillip Wylie:** And I guarantee you it wasn't segmented from the production environment. And it, the only thing in scope was that application. So you really couldn't, if this would have been a regular external pen test, then we could have, you know, tried to, See if we can do lateral movement or privilege escalation or so forth, try to gain access to other systems. And, you know, especially 2014, you know, we have, it's bad enough now that a lot of system accounts and administrator accounts are, you know, they, you know, reuse passwords and it's probably a good opportunity that there was another server using the same credentials. **22:44 Chris Romeo:** So you mentioned SQL injection. I'm always curious to understand from somebody like you who sees Lots of different systems and test different things. It seems like based on the mitigations available that we should be getting better from a SQL injection perspective because we have ORMs, we have awareness of SQL injection. Like it seems like it shouldn't be as easy as it used to be. But I'm curious, is that what you're seeing in the field as you're doing new tests these days? Or is SQL injection still as rampant as we, as it was in 2014? **23:18 Phillip Wylie:** Nah, it's, it's gotten better in some of the cases. If you see something vulnerable, you really can't do much. You may luckily get some data exposure if you're really lucky to gain, you know, 6, you know, system control is very less likely nowadays, but it, it's getting better, but you still see some of it. **23:38 Chris Romeo:** Okay. And what's the, are you seeing SSRF, for example, as You know, it, it made its way to the OWASP top 10 for, when was the last one? '21? Whatever the, whatever the last— **23:50 Robert Hurlbut:** '21. Yeah. **23:51 Chris Romeo:** Whatever the last revision, SSRF was kind of the futuristic item. They, they pick a futuristic one and add it each time. Um, like, are you seeing, has that in 5 years, 4 or 5 years, has that become something that you're seeing a lot or is it still futuristic? **24:07 Phillip Wylie:** Yeah, I don't, I'm not seeing a lot of it. **24:12 Chris Romeo:** Okay. So it's not something that's, uh, yeah, that's interesting that, uh, it's, it was a, it was kind of a guess within, within the OWASP Top 10 as far as this is something that could be. Is there anything that you're seeing new in the last couple of years that's, that you're tracking that, uh, most folks might not be aware of? **24:29 Phillip Wylie:** Yeah, nothing really that I can really, really that comes to mind. But one, one of the things that I think that's, that's worth mentioning Especially from a pen test perspective. While, you know, applications are kind of getting, getting a little bit better, but one of the things too, from internal pen test perspective, uh, application weakness vulnerabilities are one of the ways that it's easiest to gain a foothold internally. Because a lot of the pen tests I've done, I've went in, a lot of these EDRs are getting a lot more secure. It's hard to gain a foothold, but if you go in and they're running, and this is where you really see the weaknesses because A lot of these administrative consoles for security and IT tools use like a Java server, like Apache Tomcat or Red Hat JBoss. And sometimes these aren't really that secure. So sometimes that's a good way for a pentester to get a foothold. Sometimes they're vulnerable to file upload. You're able to upload a malicious file. Sometimes they're using default credentials and, and you're able to gain access with that way where otherwise trying to get a foothold in. And that's why a lot of cases, uh, that's, that's a popular method of pen testing that I really like out there is, you know, a lot of cases in the past, you went on site to do a pen test, you know, you're, you're doing an uncredentialed, unauthenticated pen test for network pen test. You're not able to gain a foothold. In a lot of cases in the past, people call it good, write it up on the pen test report. But what happens if you're an insider threat? What happens if you gain, gain access? to some credentials, you know, someone either password on a sticky note or throws away the sticky note, passwords are reused and someone finds a password dump on the dark web or whatever, because a lot of the ways as pentesters we're getting any kind of foothold externally now is finding these password dumps. So internally, you know, the password reuse and that kind of stuff. So the, the assumed breach, you know, typically this is like a white box pen test. In application pen testing where you had credentials, you do an authenticated test. Doing that on a network has a lot of value because otherwise, if you're not able to get in through the black box approach, you're not truly secure. And then also the same vulnerabilities that are used for ransomware. If someone clicks on a malicious file and affects the company with ransomware, These are some, these are authenticated users. So we need to really test authenticated on the network, taking a tip from, you know, application pen testing like we've been doing for years. **27:02 Robert Hurlbut:** I wanted to circle back on, you mentioned social engineering and I was curious about that in terms of, um, how does that get framed into the engagements? Is that, you know, 'cause you said mostly it's technical, but is that, you know, mostly physical where you're interacting with people and, and trying to do something, or could it be also technical? go with emails and other kinds of things? How does that typically factor into an engagement? **27:31 Phillip Wylie:** Yes, it's mostly going to be email, but sometimes calls, calls, vishing, you know, where you call up someone. And because, you know, these type of methods need to be tested, going back to ransomware, you know, and a lot of these different breaches, a lot of the footholds are through phishing emails or vishing. Someone calls up and persuades someone to give them credentials. Back when I was consulting, one of the tricks we would pull is we would create a website to look like a support site for that company and, and convince someone from that company to go in and log in using their corporate credentials to capture their credentials. So it's something that really needs to be used. And I think sometimes it doesn't get used enough. And one of the things I think people mistake is using the phishing campaign applications where basically you just send out an email. And it's really taking metrics of who's clicking on it and not testing security awareness. We really need to be putting payloads in those emails. What happens if someone clicks on a payload? What is, you know, available from there? I think too many people think we're just going to use these campaigns and that's good enough, which is not. You're training people and then people also within the IT organization and security organization. We did this at a company I used to work at. We knew it. We knew what not to click on, but we don't want to be bothered with it. We had set up rules that if this came through, it would send it to trash. Because, you know, there's certain headers and information, uh, URLs that some of these websites used that you're able to go through, put it in there and just direct it to your trash file in a trash bucket and not mess with it. So it's too easy to game. So I think that stuff has its place for security awareness, but you've got to build in some, some good old school phishing campaigns within those campaigns. Hmm. **29:18 Chris Romeo:** And with payloads, like I said. Yeah. So if we think about, uh, tools of the trade, you've mentioned Burp, you mentioned SQLMap. Um, I'm curious, like, what are your 5 top tools that you use for every test? **29:35 Phillip Wylie:** That's going to depend. If there's, if there's any kind of web services in there, I'm using Burp Suite. I'll use ZAP too, because one of the things Sometimes vulnerability scanners will find something that others don't. So I'll just run, uh, ZAP as a secondary to see if it finds something that maybe Burp Suite didn't find. Uh, Metasploit, if I find anything exploitable, it's also good at discovering like FTP vulnerabilities. It's got its auxiliary scanners. So Metasploit's really good. And probably Nmap is my main go-to tool because after I run a vulnerability scan, tool like scanner, like Nessus, then I go in and validate those vulnerabilities. Uh, cause it's one of the things people listening that when you do a pen test, that's kind of the difference between a vulnerability scan and like even on a vulnerability assessment, you're validating those vulnerabilities to make sure they're not false positives. Cause a lot of times these vulnerability scanners will find false positives. So my go-to tool for, for, uh, validation is like Nmap. There's a lot of Nmap scripting engine scripts or NSE scripts that look for these particular vulnerabilities, just like Log4j and some of the different vulnerabilities. You can run those to see if those systems are vulnerable. And so that's one of the tools I run that quite a bit. And then just a lot of the different tools within, within, uh, that comes installable or installed, pre-installed on Kali Linux or Parrot OS. Another tool I think is really good too is, uh, Nuclei is a good command line vulnerability scanner. I used to use Nikto a lot, which actually Project Discovery, one of the folks that wrote Nikto is contributing to Project Discovery, but Nikto was good. I heard, I used to see a lot of people downplay the effectiveness, but I've found things with Nikto that, that Burp Suite or Nessus didn't find on pen tests. So it's a really quick find. You see any kind of web services running on a system, you just run that from the command line and You can find things like default credentials or easily guessed credentials. **31:34 Chris Romeo:** And yeah, that's, uh, you're making me nostalgic now. It's, uh, it seems like Nikto is, yeah, I remember that from 10, 15 years ago as being like the, the type is like the top, one of the top tools. But, uh, yeah, it's one of those things people move on and, and tools end up going onto the shelf and not being updated and whatnot and new things, but it gives an opportunity for new things to come onto the scene as well. **32:00 Robert Hurlbut:** Yes. **32:01 Phillip Wylie:** Yeah. **32:01 Chris Romeo:** But Nmap is the, is the one that's been around. I think Nmap's been around almost as long as I have. **32:06 Robert Hurlbut:** Yeah. **32:07 Chris Romeo:** In security. And like, I got a lot of gray hair at this point. So I mean, I've been around for a while and I remember it in the early days, um, still doing, you know, the, the same basic things it did in those days. **32:18 Phillip Wylie:** Yeah. Plus they keep evolving. That's one of the things that's out of all the open source free pen testing tools or security tools out there. It's like one of the longest maintained and then Each summer they, they do this thing where people, you know, try to write different, uh, add-ons to it and enhancements and they, it keeps evolving and they keep doing good things with it. I mean, some cases people come out with other scanners that may be faster, but people may do their discovery with other scanners, but then they're going back to Nessus, to Nmap, to when you're really digging, looking for the services and vulnerabilities. **32:51 Robert Hurlbut:** So let's shift a little bit. Uh, I know that you've done some work with helping people get into, uh, this great field. And, and I mentioned some of our listeners are hearing this saying, oh, wow, you know, that's really cool. That's something I'd like to do. But what's your advice, uh, to others? How would they start? How would they get into this or even pen test related fields or careers? Yeah. **33:20 Phillip Wylie:** One of the things I would recommend is you're going to have to have the basics, basic skills to begin with. So if you're starting out totally new, then you need to understand operating systems and networking. And what could be a good place to start there is Professor Messer has some free YouTube videos based on the Security+, Network+. I think maybe it's A+. So start out learning the basics. Once you kind of get a grasp on operating systems, and networking, then you can move on to something like TryHackMe. TryHackMe has some free and low-cost, uh, memberships. I think it's like $15 a month or something like that. And there's a lot of free content. So I would start out there, build the basics up. Kind of when you get a good basic foundation built, then I would go on to like HackTheBox Academy because HackTheBox Academy has some really good educational content there. A lot of it is you need kind of some basic IT skills. And, uh, so that goes all the way from like a beginner level up to really advanced. They've got some IoT and ICS related content on there. Uh, and so it's really good content. The people that oversee that, the director there, Dimitrios, he used to be at eLearn Security. So it's similar. Some of the content is similar to eLearn Security without the videos, which, which I kind of like, you know, you. Videos are nice, but sometimes you're doing a video course, you're watching the video, then you have to keep rewinding it. I kind of like where the content is in print so you can go through and look at the content and go back and forth and read the steps instead of having to keep replaying the video. Uh, TCM Academy has some good low-cost training. Uh, as far as application security, Rana Khalil. So if you're familiar with PortSwigger's Web Application Security Academy, Rana Khalil developed a training for that. So she's got a paid course and free, so you can access her training for free on, on YouTube. And the nice thing about it is, is she does walkthroughs of the different challenges within the PortSwigger Web Application Security Academy. And if you watch the longer form videos, she shows you how to solve, uh, the labs using Python script. So it's really, really good companion to that already great free training resource. People without the experience is definitely, I would recommend using that. Someone that understands things a little bit more may not need that help, but I think it's a, it's a good companion to that. **35:47 Chris Romeo:** So we want to just mention and hear a little bit more about the book that you wrote, The Pentester Blueprint: Starting a Career as an Ethical Hacker. Is this a, By, is this biographical, biographical in that you're kind of telling your story or what, what, what is somebody going to get out of this, uh, this book? **36:09 Phillip Wylie:** Yeah. What, what people can get out of this book, where it came from is I used to teach at Dallas College. So I taught pen testing and web app pen testing there for 3 years and 8 months. And, uh, that book was based on the lecture I gave at the beginning of the semester. So I started teaching there in January. Of 2018, and I did this first day presentation sharing with my students what pen testing entails, what kind of certifications and the type of skills you need to become a pen tester. So by November 2018, I turned it into a talk and gave it at our local BSides, our BSides Dallas-Fort Worth conference, and then started giving it at a lot of conferences after that. And I was in the Tribe of Hackers Red Team book. And Wiley Publishing asked me if I had any ideas about books. And one of the things I saw every time I gave this talk, it was always a new crowd. A lot of people hadn't heard of it. I could go out today and give that talk somewhere and there'd be a lot of people that didn't hear of it. And I knew the only way to get this important content out to people is through a book because people could go to the library, rent the, you know, uh, check out the book. They could buy it online. They can find that book. And it's not based on me or my connections to be able to share it. Uh, but what the book does is based on even beyond that lecture, some of the experiences I had mentoring students and mentoring, uh, friends and people in the industry to become pentesters. So I'm sharing my experience, what I did, as well as what I recommend to others to become pentesters. Before I started teaching, I used to share resources on that I thought were valuable for prepping for the OSCP certification. So I was constantly sharing these resources. So when it came to the book, I kind of told people how to build the basics, you know, the basic fundamentals, what you needed to know, uh, some topics around cybersecurity, some of the trainings that are helpful as well as certifications helpful for being a pen tester. So it's not teaching you how to be a pen tester. It's just kind of teaching you what you need to know. and kind of pointing a direction. There's lots of great books out there on pen testing, but no one was really saying, yeah, you need to understand networking and operating systems. Someone would go to a Barnes Noble, pick up, you know, a book on pen testing, but they, they totally missed out on all this prerequisite stuff. So I share with them prerequisites and how to build that base and then resources on learning pen testing. **38:35 Chris Romeo:** Yeah, that's really cool. And I want to, um, I want to, I want to Throw something at you here. Um, and not in regards to kind of building a career. I think that's great. I think that, and people that listen to the show all the time know Robert and I are always looking for ways to resources to point people to. And 'cause we just need more people in our industry, right? Like that's just, yes, the reality. Definitely. We can, people can argue about how many people we need or how many people jobs are empty, but we know that there's a need and that, that need's gonna continue to grow. **39:05 Robert Hurlbut:** Yes. **39:05 Chris Romeo:** So I think that's awesome that you wrote that book to help people make that transition. But this, as our listeners will know, I'm about to have a soapbox moment because I, I have a number of soapbox issues or whatnot. And I guess it's a bit of a pet peeve of mine. And I'm curious to get your perspective as somebody who's helping people, uh, is an accomplished pen tester, but also helping people, you know, make it, make a, their, their journey into it. **39:30 Robert Hurlbut:** Yeah. **39:31 Chris Romeo:** And I, and the pet peeve I have is Talk to a college kid, right? That's focused on cybersecurity. And I'll ask him, he or she, what's your focus? Like, what do you want to do with your degree? Oh, I want to break stuff. I want to hack things. I want to be a pen tester. I'd say 70 to 80% of people that I ask that question to, that's their answer. And my challenge with that has always been, Pen testing is something we need. It is a control that helps us to validate all of the things that we've done earlier in the lifecycle. If we put more effort onto the building side to securely building things, we wouldn't find as many things later in the game. But I'm, do you, do you have this same experience? Like when you talk to college students, for example, and that's what they want to do. **40:22 Phillip Wylie:** And how do you, how do you wrestle with this issue? Yeah, that's one of the things too, because What do you see in the movies? Even, I forget the movie now. I think it was called Firewall that Harrison Ford was in. **40:32 Chris Romeo:** Yeah. **40:33 Phillip Wylie:** And all these security roles are always hacker-focused. It's always, and that's what entices people. It seems sexy and cool. And I think if more people knew what pen testing really entailed, they wouldn't be as interested in it because there's some boring things that go along with it. It's not always just hacking. Sometimes you're going through validating things like TLS. And SSL-related vulnerabilities that are super boring, but you've got to validate those. Then you have to write the reports. And then sometimes you have to work these crazy hours. I had customers when I was consulting, I had large airlines that I tested and my hours of testing was from 6:00 PM to 6:00 AM. And, you know, most companies you can't test until after. And if it's like just a national company in the US and they're doing business on the West Coast, then you can't test until 6 PM West Coast time and some of that. So I think really people need to get more exposure to the different areas. And one story I like to share is one of my former coworkers when I worked at US Bank. Uh, I actually had him on my, my podcast, my, my previous podcast. And when I was talking to him, he started out there on the help desk and he was taking SANS courses. for digital forensics. So he had taken several SANS courses, really loved it. And he decided, okay, the next class I'm going to take, I'm going to take the GPEN, the, you know, their basic pen testing network pen testing course, because he thought I could be a better digital forensics analyst if I understand how the hacker mind works. He took the course and fell in love with it. And now he's been pen testing for like 8 years now, something like that. And the thing to say is someone else that's interested in pentesting may take a forensics course. They may find out about threat hunting, incident response, and they may love that and like that a lot more. So I really think they need to go to conferences and different meetups, sit in on some different talks and kind of get to learn the different areas before they dive into one. And the thing is too, is maybe your end goal is to be a pentester, but any sysadmin work you do, any defensive security work you do is going to help you be a better pentester. Because one of the things I share in the book is you have to understand the technology before you can secure it. And to break into it, you need to understand the security. So once you build those fundamentals, you can move to pentesting one day if you want to. And another thing to consider too is other fields like IT. If you're starting out as a database administrator and you wanted to go over to managing networks on Cisco devices, that's a total retrain. The experience you have is going to be very limited, you know, maybe understanding some ports that Microsoft SQL or Oracle uses. That's very limited. But with, within the pen testing realm or cybersecurity, say you start out in GRC. If you work in GRC for a while and go to be a pen tester, you're going to be a lot better pen tester because you're going to understand how to work with auditors, how to work with compliance, and kind of take some of those methodology and build it into your, your pen testing. methodology and you're going to be better at it. So all this builds on each other in security. If you decide to move to something else, and you don't always stay there. Some people move out of pen testing because it's not always the best money. Some people move into management or other roles to be able to make more money. I've heard stories of people going back to working in IT because there were IT roles they can make better money at than pen testing. The problem with pen testing, there's still good salaries out there. But one of the things it does is so flooded because everyone wants to do the job. There's a lot more competition for the job. And at the same time too, some people are so desperate to do it. There's some of these people that are kind of bringing down the salaries because you got someone that, you know, oh, I'd happy to be a pen tester for $50,000, $50,000. And whenever you figure entry-level fair price should be about $80,000, but you got people that do it for less. I mean, it's. So yeah, I would say one of the things, yes. **44:27 Chris Romeo:** There's so much, there's so many, there's more people in that functional role. So it sounds like you've, you're, you're seeing the effects of what I've had as a hypothesis that too many people are focused on it. And so that's driving market rates down for what people can get paid for doing it. **44:44 Phillip Wylie:** Yes. I'm not sure how widespread that is, but just seeing how, you know, because a lot at the end of the day, companies are trying to negotiate. cheap salaries with people. I mean, and so if you're going to take this job for $30,000 less than someone else, and then you take someone that's doing a total career change that, you know, maybe they weren't even working in technology. They go out and get some pen testing certifications. They were making $40,000, you know, at this other company, you know, $10,000, $20,000 bump in pay is a lot for them. And, you know, companies, you know, they're going to want quality, but there are going to be some cases where for entry-level roles, they're just looking for someone cheap. **45:24 Chris Romeo:** Yeah. Yeah. That's why I, uh, I, I encourage these, I say kids, these college students, but I'm old enough that they're kids and just encouraging them, like, look at AppSec as a potential alternative to going down the pentesting route because we, we have even more of a shortage on the AppSec side. It's going to be, it's going to continue to be a hot, hotter and hotter area as people start to understand more about it. And so I encourage them, learn an object-oriented language, pair that with all the things you can learn about cybersecurity from whatever university program you're going through and broaden your scope a little bit and look for, look for an entry-level AppSec role. Yes, they're going to make you run tools and stuff probably in that entry-level AppSec role. It's usually what, unfortunately, that's what those often tend to be. is, oh, you're the person that runs the SaaS tool, but you can grow out of that as well and grow to a deeper, you can, you can increase your role and become a, you know, an AppSec engineer, which I think is, is just an opportunity. **46:30 Phillip Wylie:** Another thing too, if you, if you like to break things, you want to hack and you, like you said, start an entry-level AppSec role, do bug bounty, you know, in working AppSec roles, you may get to do some pen testing. So there's ways to kind of fill that need without necessarily having to be full-time pen testing role. **46:46 Chris Romeo:** Yeah. How is, um, another just off the top of my head, but I'm now, I'm really curious about this because you mentioned bug bounty. How has bug bounty changed the world of pen testing? **46:56 Phillip Wylie:** It's kind of interesting because I think if you're, if you're like a, uh, a bug hunter, if you actually do bug bounty, I think it would make you be a better pen tester because one of the things I like to Compare. I used to be a Bugcrowd ambassador and always taught, told students and mentees, if you want to get into pen testing, then you can get actual, uh, hands-on experience, you know, through, through bug bounty. But one of the things I like to describe for people to understand bug bounty, bug bounty is also crowdsourced pen testing. But the difference between bug bounty and pen testing is you get paid regardless of how good a job you do, if you find bugs or not. With bug bounty, you only get paid If you find things, and I think it'll make you a better pentester because the way I like to describe it is if you fish for sport compared to fishing to be able to feed yourself, the person that has to feed themselves from fishing is going to be a better fisherman because you, you, you find fish or you starve. You know, if you're doing it for fun, you're not going to try so hard, you know? **47:56 Chris Romeo:** Yeah. **47:57 Phillip Wylie:** I think it's the same thing with bugs, you know, finding vulnerabilities. **47:59 Chris Romeo:** That's a good, uh, that's a, that's a good analogy. I like that. I might, uh, I might borrow that and give you attribution the first or second time that I say it. After that, it'll be something that just kind of, you know, that. **48:10 Phillip Wylie:** Yeah. **48:10 Chris Romeo:** Oh, I think, Phillip, I think we could, we could, we could talk about a number of different areas here, but we're kind of running outta time for this episode, so we'll have to do another one. But we can't move forward until we do the lightning round, which Robert is, I don't know if he's famous or infamous for the lightning round. **48:28 Phillip Wylie:** Infamous, probably at this point. **48:30 Robert Hurlbut:** All right. Yeah. So we have 3 questions that we typically ask. So, uh, first is, uh, what's your most controversial opinion on application security or pen testing or, or anything related? Uh, and why do you hold that view? **48:43 Phillip Wylie:** Well, I was gonna say probably my most controversial was, was, is risk acceptance. I think there's a time and a place for it, but we can't use it for an excuse. Risk acceptance may work in the organization, but threat actors don't care if you have a risk risk acceptance. And I see people abuse it. So we really need to use it when it's needed to be used, but don't abuse it. Because it's understandable sometimes, yeah, you're not gonna be able to fix this in the 90-day allotted time that's in your policy. But at least try to, you know, get it fixed within, within a reasonable time, use those as needed and not abuse those. **49:16 Robert Hurlbut:** And next is, if you could display a message on a billboard at the RSA or Black Hat conference, what would it say? **49:27 Phillip Wylie:** Be kind. **49:28 Robert Hurlbut:** Love that. And then finally, uh, what's your top book recommendation and why do you find it valuable? **49:37 Phillip Wylie:** I'd say my top, top book recommendation would be the Web Application Hacker's Handbook because it is like one of the most comprehensive web application security and web app pen testing, uh, resources. I mean, it goes in deep in depth and is actually a lot of the content was updated on PortSwigger. It's Web Application Security Academy because they did that instead of rewriting the book. But that's one of the best resources. It goes into, I can't think of another book that goes into as much detail about application security or application pen testing than that book. **50:08 Chris Romeo:** Very cool. **50:10 Robert Hurlbut:** Yeah. **50:11 Chris Romeo:** Phillip, I want to just, I know you do podcasts and whatnot. I want to make sure our listeners know where else they can find you before we go to your key takeaway. So what, uh, what's, what podcasts are you doing right now? **50:22 Phillip Wylie:** Yes. So my podcast is the Phillip Wiley Show. I previously did the Hacker Factory podcast, but, uh, last year I went independent. And so, uh, you can find me at philipwileyshow.com. I'm on all popular podcast platforms, including YouTube. And you can find me on Twitter, formerly, or X, formerly Twitter, under Phillip Wiley and LinkedIn. And I'm always happy to ask, answer questions and do mentoring. I have calls with people from time to time. They just want to kind of get some career advice. I'll go over their LinkedIn profile or resumes and just kind of give them advice. **51:00 Chris Romeo:** And very cool. Very cool. So as far as a key takeaway, uh, or a call to action, what do you want to leave our audience with? **51:07 Phillip Wylie:** Yeah, I would say continue to learn. Don't get comfortable and just continue to learn and kind of follow your curiosity and passion. That's kind of what got me into pen testing. Within my career, I never really followed the money. It was really just following what interested me. And then fortunately it worked out to where it was areas that paid, paid decent. So just kind of continue to learn and follow your curiosity and passion. **51:26 Chris Romeo:** Awesome. Phillip, thank you for, uh, sharing your wisdom, your stories, and I can't wait to see you at a conference because I want to hear a lot more of the wrestling stories that we just ran out of time for. But I think that's fascinating, uh, that, uh, so I will find you at an event in the future. **51:44 Phillip Wylie:** And, uh, I'll come to Triangle Con and, and maybe I'll see you there and we got to, I'd love to, to hear some more of those stories. **51:51 Chris Romeo:** 'Cause that's just fascinating. That world is fascinating to me that, uh, that you've had that experience in. So, but, uh, but thanks for all you do. Thanks for, uh, sharing your wisdom and, uh, we'll have you on again in the future. Talk about something else. **52:02 Phillip Wylie:** Yeah. Thanks for having me on. Thanks for having me on, Chris. It was great to meet you in person and Robert, great to see you virtually. **52:06 Robert Hurlbut:** Same. --- Source: https://appsecpodcast.com/phillip-wylie-pen-testing-from-somebody-who-knows-about-pen-testing/