『7 Minute Security』のカバーアート

7 Minute Security

7 Minute Security

著者: Brian Johnson
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり
7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.Brian Johnson 政治・政府
エピソード
  • 7MS #740: Tales of Pentest Pwnage - Part 90
    2026/09/18

    Hey friends! We've been on a bit of a Tales of Pentest Pwnage bender lately, so let's keep it rolling with Part 90. (And Mom, relax — this is not one pentest story chopped into 90 parts.) Today is less of an A-to-Z story and more a pile of tips and tricks pulled from a recent string of SCCM-flavored internals — plus a tangent about a video game and a little robot Claude and I built to get my life back.

    • Multi-tier SCCM is having a moment — I've never administered SCCM a day in my life, but 2026 keeps dropping me into these split-role environments. Here's where I go to figure out my attack surface when all I've got is a low-priv cred.
    • SMB signing on? Cool, I'll go around it — relaying from one SCCM box to the one with SQL on it, and the easy-button tool that vacuums the good stuff out of the database once you're there. (NAA creds, clear-text local admin passwords, install scripts with creds baked in…yes please.)
    • Then relay the other direction — when the loot came back stale, a nudge from a Slack channel had me pointing the relay backwards, and I giggled like a little schoolboy at what popped out.
    • Adding yourself to the local admin group: still weirdly undetected — an old episode of ours reminded me of an Impacket tool I don't see written up on many pentest blogs, and it slipped right by.
    • My favorite cheat code hit a snag — the evil-scheduled-task-under-a-logged-in-DA trick kept coughing up permission errors, so I had to get creative. Plus the defensive recs I'm still trying to sharpen up — if you've got a better way to close this loophole, I'm all ears!
    • Tangent: Halloween (the video game) and the lobby watcher — a million players and I'm still staring into the lobby abyss for 10 minutes at a time. So Claude and I built something that watches the screen and texts me when it's time to sprint back to the keyboard. It's not cheating. It's not! (The Texas Chainsaw crowd disagreed, loudly.)
    続きを読む 一部表示
    34 分
  • 7MS #739: Tales of Pentest Pwnage – Part 89
    2026/09/11

    Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I'm absolutely going to say it was intentional and that I totally meant to do that.

    Here's what we cover:

    • A client that's actually doing the things – year two or three of testing this environment, and they had buttoned up so much that I had to dig deep. Great for them, freaking frustrating for me.
    • Why my Kerberoasting success rate has fallen off a cliff – Microsoft pushed an encryption change earlier this year, and cracking those hashes is a whole different ballgame now.
    • Selective poisoning vs. poison-all-the-things – a nod to Pretender, which I covered in a TuesdayTOOLSday video over at 7MinSec.club. It doesn't get nearly enough love in blogs and videos.
    • The relay that fired… and did something completely different than I expected – I saw the ntlmrelayx log scroll by, thought "yes, I've got DA," and then had a "wait, wait, whoa, what?" moment. I was honestly a little panicked.
    • An ancient Exchange vulnerability comes back to bite – CVE-2021-34470 (vulnerable Exchange schema) turned out to be the fallback that got me a foothold I had no business having.
    • My favorite evil privesc trick, revisited – queuing up a scheduled task that runs under an interactively logged-in DA's context without ever knowing their password. The MDR alerts that come out of this are equal parts hilarious and terrifying.
    • A bonus thing to always look for – scheduled tasks running under saved DA creds that point at a script you can edit. Add one little line to fire an evil command of your choice, and you're in like a dirty shirt.

    Check us out at 7MinSec.com for pentesting, training, controls assessments and security miscellany, 7MinSec.club for our Substack and weekly TuesdayTOOLSday videos, and 7MinSec.wiki for tips, cheat sheets and scripts (including pages on the scheduled task shenanigans above).

    続きを読む 一部表示
    18 分
  • 7MS #738: Baby's First ProjectDiscovery Neo
    2026/09/04

    Hey friends! Today I'm talking about Baby's First Neo — and to be crystal clear, I don't mean Keanu, and I don't mean the R&B guy with the hat. I mean the AI-powered pentest assistant from our pals at ProjectDiscovery. Also to be crystal clear: this is not a sponsorship, ad, partnership or anything of the sort. Just me sharing a thing I like so you can decide if you like it too.

    Here's what we get into:

    • Why I didn't renew my ProjectDiscovery cloud subscription after a full year of running it side-by-side with Nessus — including the three things that ground my gears (one of which had me angry like the Hulk inside)
    • The Palo Alto finding that made me plunk down a credit card and buy PD in the first place
    • What happened when I actually told their team why I was canceling — and the surprise offer that followed
    • How I set up my first Neo project, and the multi-paragraph prompt I fed it (spoiler: "please don't go rogue" was in there)
    • Where Neo beat my manual process — and the two subdomains it found that I flat-out missed
    • The OSINT recommendation Neo made about a job posting that I thought was genuinely smart
    • My one big hesitation about the credit-based pricing model, and why a part two of this series is probably coming soon

    Then we close out with the tangent portion of the program: Grandma 7MS might be my neighbor soon, she bought a vehicle roughly the size of a small nation, and I'm asking for some good vibes on her house hunt. Also, thank you again to everybody who has sent kind messages since my dad passed — it means more than you know.

    続きを読む 一部表示
    29 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません