TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    7 Minute Security

    7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.

    Advertise

    Copyright: © Brian Johnson

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    7MS #421: Cyber News - Verizon DBIR Edition Jul 01, 2020
    Show notes

    Today my pal Gh0sthax and I pick apart the Verizon Data Breach Investigations Report and help you turn it into actionable items so you can better defend your network!

    I'm especially excited because today's episode marks two important 7MS firsts:

    • The episode has been crafted by a professional podcast producer
    • The episode has been transcribed by a professional transcription service

    7MS #420: Tales of Internal Pentest Pwnage - Part 17 Jun 26, 2020
    Show notes

    Today's episode is a fun tale of pentest pwnage! Interestingly, to me this pentest had a ton of time-sponging issues on the front end, but the TTDA (Time to Domain Admin) was maybe my fastest ever.

    I had to actually roll a fresh Kali VM to upload to the customer site, and I learned (the hard way) to make that VM disk as lean as possible. I got away with a 15 gig drive, and the OS+tools+updates took up about 12 gig.

    One of the biggest lessons I learned from this experience is to make sure that not only is your Kali box updated before you take it to a customer site (see this script), but you should make sure you install all the tool dependencies beforehand as well (specifically, Eyewitness, Impacket and MITM6).

    This pentest was also extremely time-boxed, so I tried to get as much bang out of it as possible. This included:

    • Capturing hashes with Responder
    • Checking for "Kerberoastable" accounts (GetUserSPNs.py -request -dc-ip x.x.x.x domain/user)
    • Check for MS14-025 (see this article)
    • Check for MS17-010 (nmap -Pn -p445 --open --max-hostgroup 3 --script smb-vuln-ms17-010 192.168.0.0/24 -oA vulnerable-2-eblue) and try this method of exploiting it
    • Check for DNS zone transfer (dnsrecon -d name.of.fqdn -t axf)
    • Test for egress filtering of ports 1-1024
    • Took a backup of AD "the Microsoft way" and then cracked with secretsdump:

    sudo python ./secretsdump.py -ntds /loot/Active\ Directory/ntds.dit -system /loot/registry/SYSTEM -hashes lmhash:nthash LOCAL -outputfile /loot/ad-pw-dump


    7MS #419: Eating the Security Dog Food Jun 17, 2020
    Show notes

    Today we're talking about eating the security dog food! What do I mean by that? Well, a lot of security companies I worked for in the past preached to clients about the importance of having a good security program, but didn't have one of their own! I'm trying to break that pattern now that I'm in a position to lead an information security program for 7MS.

    In today's episode we talk about getting your company started with a good set of infosec policies/procedures. First up is a "mothership" infosec policy with the following sub-policies inside it:

    • Acceptable Use
    • Data Protection and Privacy
    • Physical Security
    • Tools and Technology
    • Training and Awareness
    • Reporting

    Oh, and the song I jazz/scat/sang coming out of the jingle was If I Were a Dog


    7MS #418: Securing Your Mental Health Jun 11, 2020
    Show notes

    SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit safepass.me for more details, and tell them 7 Minute Security sent you to get a 10% discount!

    Today's episode is all about mental health! I talk about some of my challenges with stress/anxiety and how I finally put on my big boy pants, dropped some misconceptions and decided to do something about it. Additionally, this episode contains references to:

    • Jon Secada
    • Arsenio Hall
    • Lone Wolf McQuade

    7MS #417: Vulnerability Scanning Tips and Tricks Jun 04, 2020
    Show notes

    Today's episode is all about getting the most value out of your vulnerability scans, including:

    • Why, IMHO you should only do credentialed scans

    • Policy tweaks that will keep servers from tipping over and printers from printing novels of gibberish ;-)

    • How to make your scan report more actionable and less unruly

    • Turning up logging to 11 (use with caution!)

    • A small tweak to an external scan policy that can result in the difference between a successful or failed scan

    • The nessusd.rules file is awesome for excluding specific hosts and services from your scans


    7MS #416: Pi-hole 5.0 May 28, 2020
    Show notes

    This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit Arcticwolf.com/7MS to learn more.

    Today we're talking about some of my favorite features of Pi-hole 5.0. Including:

    • WARNING! WARNING! Upgrading from 4.x is a one-way operation!

    • Per-client blocking (you can setup, for example, a group machines called "kids" and apply specific domain block/allow lists and domains to them)

    • More granular detail (especially if there are issues) when blocklists get updated

    • Better, richer debug log output

    I also talk about a great companion for yor Pi-hole: a command-line Internet speed test! Hat tip to Javali over at the 7MS forums who told me about this.

    Additionally, I briefly mention "Hashy" (the nickname of my password cracking rig), give you some stay-at-home streaming TV show recommendations, and give you a quick house rebuild update!


    7MS #415: Cyber News May 21, 2020
    Show notes

    Today's episode kicks off a fun little experiment where my pal Joe Skeen and I cover some of the week's interesting security news stories, how they might affect you, and what you can do to make you and your company more secure. This week's stories:

    • Salt stack RCE (Daily Swig / Cyber Scoop)

    • Malware uses Corporate MDM as attack vector (Checkpoint)

    • Critical vulns in Sharefile (Citrix)

    • Shareholders sue Labcorp over their 'persistent' failure to secure data (Cyberscoop)


    7MS #414: Tales of Pentest Fail #4 May 14, 2020
    Show notes

    SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit safepass.me for more details, and tell them 7 Minute Security sent you to get a 10% discount!

    Today I'm excited to share more tales of pentest FAIL with you. Today's tales include:

    1. Accidentally scanning assets that belong to an agency that nobody should be messing with

    2. Delivering reports with vulnerabilities from somebody else's network

    3. Why it's important to write a report more than 15 minutes before delivery

    4. Lessons learned from firing a disgruntled employee


    7MS #413: PCI Professional Certification (PCIP) - Part 3 May 07, 2020
    Show notes

    Hey everybody! I hope you're hanging in there during quarantine and staying healthy. Today is part 3 of our ongoing series all about becoming a PCIP. The good news is I'm finally, actually registered for the cert and have started diving into the training! So in today's episode I want to regurgitate some of what I'm learning to whet your appetite (or not) for this particular certification. Specifically, we cover:

    • The overview and objectives for being a PCIP (TLDR: PCIP does NOT replace QSA or ISA, but gives us a good understanding of how to protect payment card data)

    • How and why payment card data is leaked/stolen/breached - and then sold/monetized

    • The definition of some fundamental PCI acronym soup, including PCI DSS, PA-DSS and P2PE


    7MS #412: Tips for Working Safely and Securely From Home May 01, 2020
    Show notes

    This podcast is sponsored by Arctic Wolf, whose Concierge Security teams Monitor, Detect and Respond to Cyber threats 24/7 for thousands of customers around the world. Arctic Wolf. Redefining cybersecurity. Visit Arcticwolf.com/7MS to learn more.

    In today's episode we share some tips for working more safely and securely from home, which for many of us is our new office for the foreseeable future! Specifically, we cover:

    • Picking powerful passwords
    • Locking down your wifi
    • Defending your digital identity
    • Protecting your PC
    • Blocking icky stuff in your browser
    • Composing careful conference calls
    • Clicking links carefully

    I've also made this episode available in long-form blog here. Please feel free to share with anybody you think could benefit from the info!


    Previous 1 31 32 33 34 35 75 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights