Skip to content
PodcastsTechnologyDavid Bombal

David Bombal

David Bombal
David Bombal
Latest episode

596 episodes

  • David Bombal

    #600: This Free Tool Decodes Game Boy ROM From a Photograph

    02/09/2026 | 41 mins.
    Can you recover working software from a photograph of a microchip?

    Embedded systems reverse engineer Travis Goodspeed demonstrates how to extract the original Game Boy’s 256-byte boot ROM from a microscopic photograph of the mask ROM inside its CPU.

    The source image was created by combining 22 microscope photographs captured at 50x magnification. Using his free, open-source Mask ROM Tool, Travis marks 2,048 ROM bit locations, separates the ones from the zeros and checks for possible recognition errors. He then determines the logical order of the bits, disassembles the program and shows how it can be exported as a ROM file for use in an emulator.

    Travis also explains the Game Boy’s unusual copy-protection system. During startup, its boot ROM displays logo data supplied by the cartridge and compares it with Nintendo’s internal copy. If the logos do not match, the game does not boot. Requiring cartridges to contain Nintendo’s trademark gave the company legal leverage against unlicensed publishers.

    The video also explores techniques from Travis’s book, Microcontroller Exploits. These include extracting protected firmware from an access-control reader, chemically decapsulating chips while preserving their operation and using ultraviolet light with a nail-polish mask to remove memory protection without erasing the program.

    The Mask ROM Tool, Game Boy chip photograph and step-by-step tutorial are publicly available, allowing you to reproduce the ROM-decoding demonstration without owning a microscope or chemistry lab.

    // Sponsored SEGMENT //
    Big thank you to Proton Pass for sponsoring this video. Take your security to the next level by getting Proton Pass using the following be www.proton.me/davidbombal

    // Link to No Starch Website for Travis’ Book //
    Order Microcontroller Exploits and get the eBook free.
    https://nostarch.com/microcontroller-...

    Use Coupon Code GOODSPEED25 for 25% off Microcontroller Exploits at NoStarch.com

    // Travis Goodspeed SOCIAL //
    GitHub: https://github.com/travisgoodspeed

    // GitHub link to GameBoy ROM Tutorial //
    https://github.com/travisgoodspeed/gb...

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU//
    0:00 - Coming Up
    0:40 - Intro
    03:28 - Book Overview
    05:27 - Proton Pass Ad
    07:29 - Demonstration Context
    09:56 - Demo Begins
    12:48 - Marking the Chip Rows
    18:27 - How Travis Wrote his Book
    19:55 - Design Rule Check
    23:11 - How to Decode the Binary
    28:36 - Can the Binary Numbers Change?
    30:30 - Why is this Method Useful?
    34:24 - More book Overviews
    40:48 - Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #gameboy #reverseengineering #rom
  • David Bombal

    #599: This Pocket Tool Diagnoses Wi-Fi in 45 Seconds

    02/09/2026 | 42 mins.
    Your internet speed can look fine while your Wi-Fi is still failing. Packet loss, latency, congested channels, interference and poor configuration can all damage performance, but a normal speed test will not show you the full picture.

    In this video, I test the Ookla Speedtest Pulse, a pocket-sized Wi-Fi 7 diagnostic tool that measures more than 25 network metrics in around 45 seconds. We test Wi-Fi at the Natural History Museum in London and examine results from an Airbnb to identify whether the problem comes from the Wi-Fi network, wired connection or internet service provider.

    Matt explains how the device tests 2.4, 5 and 6 GHz Wi-Fi, detects channel problems, measures signal quality and gives you practical recommendations in plain English.

    We also compare Speedtest Pulse with the normal Speedtest application, laptopbased tools and the Ekahau Sidekick 2. You will see its current limitations, upcoming continuous monitoring features and how it could help technicians finally capture intermittent Wi-Fi problems.

    Big thanks to OOKLA for sponsoring this video. To get your own Speedtest Pulse please use the following link: https://wifi.ekahau.com/david-bombal-...

    // Matt Starling’s SOCIAL //
    LinkedIn: / matt-starling-03913633
    X: https://x.com/mattstarling?s=21

    // Ookla’s SOCIAL //
    LinkedIn: / ookla

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:58 - Testing Public Wi-Fi in London
    01:40 - What Is the Speedtest Pulse?
    03:40 - Pulse vs Speedtest vs Sidekick 2
    06:19 - Making Wi-Fi Troubleshooting Easy
    07:44 - Running a Wi-Fi Test
    09:22 - Understanding Wi-Fi Performance Scores
    11:16 - Reports and Cloud Results
    13:00 - Active vs Continuous Pulse
    15:14 - Wired and Wireless Network Testing
    18:05 - Why Not Just Use a Laptop?
    21:02 - Mobile Support and Wi-Fi 7 Hardware
    23:17 - Understanding Your Wi-Fi Score
    26:54 - Wi-Fi Security and PMF
    29:03 - Signal Strength and Transmit Power
    30:19 - Wi-Fi Channels and Interference
    31:58 - How to Improve Your Wi-Fi
    33:12 - WPA3 Best Practices
    34:16 - Price and Coverage Mapping
    35:59 - Pulse vs Sidekick 2 for Interference
    38:36 - Solving Intermittent Wi-Fi Problems
    40:32 - Cloud Monitoring and Multi-Site Management
    42:12 - Final Thoughts

    Please note that links listed may be affiliate links and provide me with a small
    percentage/kickback should you use them to purchase any of the items listed or recommended.
    Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #ookla #speedtest #wifi
  • David Bombal

    #598: AI Can’t Understand Intent. That’s a Security Problem

    26/08/2026 | 26 mins.
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

    AI is changing cybersecurity, but simply using more AI to defend against AI attacks may not be the answer.

    David Bombal sits down with Danny Jenkins, CEO of ThreatLocker, to discuss the security risks created by AI, autonomous agents, zero-day vulnerabilities, ransomware, and the rapidly expanding attack surface businesses now have to deal with.

    Danny explains one of the fundamental problems with AI security: AI can understand what something does, but it may not understand the intent behind it. The same action could be performed legitimately by an administrator or maliciously by an attacker.

    They also discuss how AI is giving attackers capabilities that previously required significantly more expertise and resources, including vulnerability discovery and
    sophisticated phishing attacks.

    But AI creates another problem inside organizations. Autonomous agents can potentially access files, upload data, perform actions, and make mistakes extremely quickly. Every new piece of software adds attack surface, and powerful AI agents can dramatically increase that risk. Danny argues that the answer isn't simply AI versus AI.
    Instead, organizations need to rethink trust itself.

    The discussion covers deny by default, application control, restricting what software and AI agents are allowed to access, and why AI should be used as an additional
    security layer rather than becoming your primary defense.

    Topics include:
    • AI security risks
    • Autonomous and agentic AI
    • Why AI struggles with intent
    • How hackers are using AI
    • AI-powered vulnerability discovery
    • Zero-day vulnerabilities
    • Ransomware
    • AI attack surfaces
    • Application control
    • Deny by default security
    • Why AI alone can't solve AI security
    • Securing AI inside businesses

    // Danny Jenkins’ SOCIAL //
    LinkedIn: / dannyjenkinscyber

    // ThreatLocker’s SOCIAL //
    LinkedIn: https://www.linkedin.com/company/thre...
    X: https://x.com/threatlocker
    Instagram: / threatlocker
    Website: https://www.threatlocker.com/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:34 - Introduction
    0:46 - Why Businesses Are Afraid of AI
    02:17 - AI Can Be Used for Good or Bad
    03:29 - The Race to Adopt AI
    05:02 - AI Gives Attackers Nation-State Capabilities
    06:09 - Why AI Can't Be Your Primary Defense
    07:59 - How AI Is Expanding the Attack Surface
    08:53 - Solving AI Security With Limited Access
    11:04 - The Deny-by-Default Security Model
    14:12 - AI-Powered Vulnerability Hunting
    17:29 - How ThreatLocker Actually Uses AI
    20:01 - Why Deny-by-Default Beats Chasing Zero-Days
    21:15 - What Cybersecurity Customers Are Most Worried About
    22:16 - AI Hype, Jobs & Closing Thoughts
    24:55 - ThreatLocker Advert

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #threatlocker #bhusa2026 #blackhat
  • David Bombal

    #597: The Hacking Gadgets You Need to Know

    24/08/2026 | 42 mins.
    Note: Hak5 did not pay me to make this video. But, I'm marking it as sponsored because Darren was kind enough to give me some cool Hak5 gadgets. Get your own using my link: https://davidbombal.wiki/gethak5

    // Darren Kitchen SOCIAL //
    YouTube: https://www.youtube.com/darrenkitchen
    Website: https://hak5.org/pages/hack-across-america
    X: https://x.com/hak5darren

    // Hak5 WEBSITE (affiliate) //
    https://davidbombal.wiki/gethak5

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU//
    0:00 - Coming up
    01:00 - 21 Years of Hak5 // Device overview
    05:30 - USB Rubber Ducky
    09:22 - Bash Bunny
    12:41 - Plunder Bug
    13:28 - Shark Jack & Shark Jack Display
    16:28 - Packet Squirrel
    18:51 - Key Croc
    21:51 - Screen Crab
    24:07 - Lan Turtle Hub
    28:14 - WiFi Pineapple
    33:16 - WiFi Pineapple Pager
    37:32 - Hak5 books
    39:15 - Darren's favourite tools
    41:27 - Future projects // Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.

    #hak5 #hackinggadgets #hacktool
  • David Bombal

    #596: This is the Real Cybersecurity Problem

    20/08/2026 | 28 mins.
    Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people.

    Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem.

    For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place.

    They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it.

    Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders.

    Topics include:
    Why cybersecurity may be a software quality problem
    Why users are blamed for insecure software
    CISA’s Secure by Design initiative
    Why default passwords should disappear
    AI agents behaving in unexpected ways
    AI and the future of zero-day attacks
    Memory safety, C, C++ and Rust
    Government regulation and vendor accountability
    The EU Cyber Resilience Act
    Why Patch Tuesday may eventually become unacceptable
    How AI could help defenders find and fix vulnerabilities
    Jen Easterly’s advice for cybersecurity professionals

    If you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don’t want to miss.

    // Jen Easterly’s SOCIAL //
    LinkedIn: / jen-easterly

    // Website REFERENCE //
    https://www.cisa.gov/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming up
    0:55 - Jen Easterly introduction & background
    04:20 - Advice for the youth
    07:10 - Advice for ethical hackers and leadership
    11:35 - Software security // Who's to blame?
    17:39 - Power and responsibility
    21:17 - Secure by design
    26:38 - Is it important to attend RSAC? // Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #rsac #bhusa2026 #securebydesign
More Technology podcasts
About David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place! On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics. This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content. David’s details: Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co Website: http://www.davidbombal.com YouTube: https://www.youtube.com/davidbombal All the best! David
Podcast website

Listen to David Bombal, Search Engine and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features