7MS #420: Tales of Internal Pentest Pwnage - Part 17
7 Minute Security26 Juni 2020

7MS #420: Tales of Internal Pentest Pwnage - Part 17

Today's episode is a fun tale of pentest pwnage! Interestingly, to me this pentest had a ton of time-sponging issues on the front end, but the TTDA (Time to Domain Admin) was maybe my fastest ever.

I had to actually roll a fresh Kali VM to upload to the customer site, and I learned (the hard way) to make that VM disk as lean as possible. I got away with a 15 gig drive, and the OS+tools+updates took up about 12 gig.

One of the biggest lessons I learned from this experience is to make sure that not only is your Kali box updated before you take it to a customer site (see this script), but you should make sure you install all the tool dependencies beforehand as well (specifically, Eyewitness, Impacket and MITM6).

This pentest was also extremely time-boxed, so I tried to get as much bang out of it as possible. This included:

  • Capturing hashes with Responder
  • Checking for "Kerberoastable" accounts (GetUserSPNs.py -request -dc-ip x.x.x.x domain/user)
  • Check for MS14-025 (see this article)
  • Check for MS17-010 (nmap -Pn -p445 --open --max-hostgroup 3 --script smb-vuln-ms17-010 192.168.0.0/24 -oA vulnerable-2-eblue) and try this method of exploiting it
  • Check for DNS zone transfer (dnsrecon -d name.of.fqdn -t axf)
  • Test for egress filtering of ports 1-1024
  • Took a backup of AD "the Microsoft way" and then cracked with secretsdump:

sudo python ./secretsdump.py -ntds /loot/Active\ Directory/ntds.dit -system /loot/registry/SYSTEM -hashes lmhash:nthash LOCAL -outputfile /loot/ad-pw-dump

Avsnitt(720)

7MS #327: Interview with John Strand

7MS #327: Interview with John Strand

Today's episode is brought to you by my friends at Netwrix. Their amazing Netwrix Auditor tool gives you visibility into what's happening both on your local network and cloud-based IT systems and tell...

13 Sep 201846min

7MS #326: Interview with Ryan Manship and Dave Dobrotka

7MS #326: Interview with Ryan Manship and Dave Dobrotka

Today's episode is brought to you by my friends at Dashlane, a fantastic password manager for you, your family and your business! Head to www.dashlane.com/7ms and use the code 7MS for 10% off a year o...

6 Sep 20181h 33min

7MS #325: Integrating Pwned Passwords with Active Directory - Part 2

7MS #325: Integrating Pwned Passwords with Active Directory - Part 2

Today's episode is a follow-up to #304 where we talked about how you can integrate over 500 million weak/breached/leaked passwords form Troy Hunt's Pwned Passwords into your Active Directory. To get s...

30 Aug 201819min

7MS #324: How to Succeed in Business Without Really Crying - Part 4

7MS #324: How to Succeed in Business Without Really Crying - Part 4

It's been a while so I thought I'd update you on how things are going on the business front. Here are the big updates I want to share with you in today's episode: A new 7MS hire that's going to hunt ...

23 Aug 201820min

7MS #323: 7 Ways to Not Get Hacked

7MS #323: 7 Ways to Not Get Hacked

I'm putting together a general security awareness session aimed at helping individuals and businesses not get hacked. To play off the lucky number 7, I'm trying to broil this list down to 7 key things...

16 Aug 201818min

7MS #322: My First Live Radio Interview

7MS #322: My First Live Radio Interview

I had an exhilarating and terrifying experience this week doing my first ever live radio interview! As a quick bit of background, this interview was part of the 7MS radio marketing campaign that I've ...

9 Aug 201853min

7MS #321: Interview with Joe Klein - Part 2

7MS #321: Interview with Joe Klein - Part 2

Today's episode is brought to you by ITProTV. Visit itpro.tv/7ms and use code 7MS to get a FREE 7-day trial and 30% off a monthly membership for the lifetime of your active subscription. Today's epis...

1 Aug 20181h 47min

7MS #320: Interview with Lane Roush of Arctic Wolf

7MS #320: Interview with Lane Roush of Arctic Wolf

Today's episode is brought to you by ITProTV. Visit itpro.tv/7ms and use code 7MS to get a FREE 7-day trial and 30% off a monthly membership for the lifetime of your active subscription. This week I ...

25 Juli 20181h 3min

Populärt inom Politik & nyheter

aftonbladet-krim
p3-krim
politiken
rss-krimstad
aftonbladet-daily
svenska-fall
spar
flashback-forever
rss-sanning-konsekvens
rss-krimreportrarna
kungligt
rss-expressen-dok
rss-frandfors-horna
motiv
rss-flodet
blenda-2
rss-vad-fan-hande
krimmagasinet
ett-rent-noje
svd-ledarredaktionen