7MS #426: Tales of Internal Pentest Pwnage - Part 19

7MS #426: Tales of Internal Pentest Pwnage - Part 19

This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit Arcticwolf.com/7MS to learn more.

First and foremost, I have to say that 7 Minute Security's official stance on toads is that nobody should be licking them at any time, for any reason. Also, I can neither confirm nor deny that toads can catch coronavirus. Listen to today's episode...it'll make more sense.

We've got another swell tale of internal pentest pwnage for you today! Highlights include:

  • If you've collected a ton of hashes with Responder, the included DumpHash.py gives you a lovely organized list of collected hashes!

  • Here's one way you can grab the latest CME binary:

curl https://github.com/byt3bl33d3r/CrackMapExec/releases/download/v5.0.1dev/cme-ubuntu-latest.zip -L -o cme.zip

Note to self: I must've been using outdated CME forever, because the correct syntax to get the wdigest flag is now a little different:

cme smb HOST -u localadmin -H "hash" --local-auth -M wdigest -o ACTION=enable
  • If you're looking to block IPv6 (ab)use in your environment, this article has some great tips.

  • When testing in an environment with a finely tuned SIEM, I highly recommend you download all the Kali updates and tools ahead of time, as sometimes just the call out to kali.org gets flagged and alerted on to the security team

  • Before using the full hatecrack methodology, I like to run hashes straight through the list of PwnedPasswords from hashes.org (which appears to currently be offline) first to give the org an idea as to what users are using easy-to-pwn passwords.

  • A question for YOU reading this: what's the best way to do an LSASS dump remotely without triggering AV? I can't get any of the popular methods to work. So pypykatz is my go-to.

  • I learned that PowerView is awesome for finding attractive shares! Run it with Find-InterestingDomainShareFile to find, well, interesting files! Files with password or sensitive or admin in the title - and much more!

  • Got to use PowerUpSQL to audit some MS SQL sauce, and I found this presentation (specifically slide ~19) really helpful in locating servers I could log into and any SQL vulnerabilities the boxes were ripe for.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(741)

7MS #741: Tales of Pentest Pwnage - Part 91

7MS #741: Tales of Pentest Pwnage - Part 91

Hey friends! Today's tale of pentest pwnage is brought to you by four hours of sleep, a large mint hot cocoa, and unhealthy levels of giggity. There's a very good reason for all three, but you'll have...

25 Sep 36min

7MS #740: Tales of Pentest Pwnage - Part 90

7MS #740: Tales of Pentest Pwnage - Part 90

Hey friends! We've been on a bit of a Tales of Pentest Pwnage bender lately, so let's keep it rolling with Part 90. (And Mom, relax — this is not one pentest story chopped into 90 parts.) Today is les...

18 Sep 33min

7MS #739: Tales of Pentest Pwnage – Part 89

7MS #739: Tales of Pentest Pwnage – Part 89

Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened c...

11 Sep 17min

7MS #738: Baby's First ProjectDiscovery Neo

7MS #738: Baby's First ProjectDiscovery Neo

Hey friends! Today I'm talking about Baby's First Neo — and to be crystal clear, I don't mean Keanu, and I don't mean the R&B guy with the hat. I mean the AI-powered pentest assistant from our pals at...

4 Sep 29min

7MS #737: Tales of Pentest Pwnage – Part 88

7MS #737: Tales of Pentest Pwnage – Part 88

Hello friends! Today's tale of pentest pwnage isn't a start-to-finish march to DA – it's me finally emptying out the backlog of "gosh, I've got to share this next time" internal network tips that have...

28 Aug 33min

7MS #736: Securing Your Family During and After a Disaster – Part 9

7MS #736: Securing Your Family During and After a Disaster – Part 9

Hey friends! Today's another slice of our Securing Your Family During and After a Disaster miniseries, and fair warning — it's a bit of a Friday mood-ruiner. It's been almost two months since my dad p...

21 Aug 29min

7MS #735: Baby's First Cloudflare Tunnel

7MS #735: Baby's First Cloudflare Tunnel

Hey friends! Today's episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a...

14 Aug 24min

7MS #734: Insight Recon

7MS #734: Insight Recon

Hey friends! Today's episode is a two-parter: some security stuff up front, and then a big ol' personal celebration on the back half. If you're strictly here for the security bits, I love you and you'...

7 Aug 32min

Populärt inom Politik & nyheter

svenska-fall
aftonbladet-krim
fordomspodden
p3-krim
rss-krimstad
flashback-forever
rss-expressen-dok
spar
aftonbladet-daily
rss-vad-fan-hande
rss-sanning-konsekvens
svd-ledarredaktionen
rss-krimreportrarna
politiken
rss-flodet
rss-utopia-2
omni-podd
rss-frandfors-horna
motiv
kungligt