7MS #514: Tales of Pentest Pwnage - Part 34
7 Minute Security30 Maalis 2022

7MS #514: Tales of Pentest Pwnage - Part 34

Welcome to another fun tale of pentest pwnage! This one isn't a telling of one single pentest, but a collection of helpful tips and tricks I've been using on a bunch of different tests lately. These tips include:

  • I'm seeing nmap scans get flagged a bit more from managed SOC services. Maybe a "quieter" nmap scan will help get enough ports to do a WitnessMe run, but still fly under the logging/alerting radar? Something like: nmap -p80,443,8000,8080 subnet.i.wanna.scan/24 -oA outputfile

  • Using mitm6 in "sniper" mode by targeting just one host with: mitm6 victim-I-want-to-get-juicy-info-from -d victim.domain --ignore-nofqnd

  • Using secretsdump to target a single host: secretsdump.py -target-ip 1.2.3.4 localadmin:@1.2.3.4 -hashes THIS-IS-WHERE-THE:SAM-HASHES-GO. Note the colon after localadmin - it's intentional, NOT an error!

  • Rubeus makes password spraying easy-peasy! Rubeus.exe spray /password:Winter2022 /outfile:output.txt. Get some hits from that effort? Then spray the good password against ALL domain accounts and you might get even more gold!

  • LDAPs relaying not working? Make sure it's config'd right: nmap -p636 -sV -iL txt-file-with-dcs-in-it

Jaksot(711)

7MS #55: OFFTOPIC – What's in Brian's Murse? (video)

7MS #55: OFFTOPIC – What's in Brian's Murse? (video)

Ok I don't really have a murse, but I wanted to do a short video(!) podcast to show you some sorta-security-related gadgets that I've been nerding out on the last few weeks. 7MS #55: OFFTOPIC – What's...

22 Huhti 20156min

7MS #54: Traveling with a Red Giant (audio)

7MS #54: Traveling with a Red Giant (audio)

If you're concerned about your credit/debit card security, you might want to give Red Giant a try. It's a service that provides a debit card you can unlock *only* when buying something. It's cool. Oh,...

16 Huhti 20157min

7MS #53: Are You Ready to Get Robbed? (audio)

7MS #53: Are You Ready to Get Robbed? (audio)

Business DR plans are a hugely important – and often overlooked – piece of the infosec puzzle. But what about at home? If you got run over by a bus tomorrow, would you have good plans in place to help...

14 Huhti 20157min

7MS #52: OFFTOPIC – My Son is Really Loyal (audio)

7MS #52: OFFTOPIC – My Son is Really Loyal (audio)

It's another off-topic episode today. This one's about how my eight-year-old son is fiercely loyal, and wants to settle a 25-year-old score for me. 7MS #52: OFFTOPIC – My Son is Really Loyal (audio)

9 Huhti 20158min

7MS #51: CEH vs. OSCP (audio)

7MS #51: CEH vs. OSCP (audio)

A few people have written in asking whether to pursue the CEH or OSCP (or both). This episode discusses my experience with each cert and hopefully points you in the right direction on which one might ...

7 Huhti 20157min

7MS #50: OSCP – The Final Chapter – part 2! (audio)

7MS #50: OSCP – The Final Chapter – part 2! (audio)

At last, the epic conclusion of the maddening, redeeming OSCP journey. 7MS #50: OSCP – The Final Chapter – part 2! (audio)

2 Huhti 20157min

7MS #49: OSCP – The Final Chapter – part 1! (audio)

7MS #49: OSCP – The Final Chapter – part 1! (audio)

We've arrived at the exciting two-part finale to my bloody battle with the OSCP! 7MS #49: OSCP – the final chapter – part 1! (audio)

31 Maalis 20157min

7MS #48: So I Gave My Eight Year Old a Computer (audio)

7MS #48: So I Gave My Eight Year Old a Computer (audio)

Is it a good idea to give young kids a computer to play with? Maybe. Maybe not. Tune in to today's episode and weigh in! 7MS #48: So I Gave My Eight Year Old a Computer (audio)

21 Maalis 20158min

Suosittua kategoriassa Politiikka ja uutiset

aikalisa
politiikan-puskaradio
rss-ootsa-kuullut-tasta
tervo-halme
ootsa-kuullut-tasta-2
viisupodi
rss-vaalirankkurit-podcast
et-sa-noin-voi-sanoo-esittaa
rss-asiastudio
rss-podme-livebox
otetaan-yhdet
rss-hyvaa-huomenta-bryssel
aihe
radio-antro
rss-kiina-ilmiot
rss-tasta-on-kyse-ivan-puopolo-verkkouutiset
rss-vain-talouselamaa
the-ulkopolitist
rss-kovin-paikka
rss-sanna-ukkola-show-verkkouutiset