『7 Minute Security』のカバーアート

7 Minute Security

7 Minute Security

著者: Brian Johnson
無料で聴く

このコンテンツについて

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.Brian Johnson 政治・政府
エピソード
  • 7MS #695: Tales of Pentest Pwnage - Part 78
    2025/10/03

    Today’s tale of pentest pwnage involves:

    • Using mssqlkaren to dump sensitive goodies out of SCCM
    • Using a specific fork of bloodhound to find machines I could force password resets on (warning: don’t do this in prod…read this!)

    Don’t forget to check out our weekly Tuesday TOOLSday – live every Tuesday at 10 a.m. over at 7MinSec.club!

    続きを読む 一部表示
    16 分
  • 7MS #694: Tales of Pentest Pwnage – Part 77
    2025/09/26

    Hey friends, today I talk about how fun it was two combine two cool pentest tactics, put them in a blender, and move from local admin to mid-tier system admin access (with full control over hundreds of systems)! The Tuesday TOOLSday video we did over at 7minsec.club will help bring this to life as well.

    続きを読む 一部表示
    33 分
  • 7MS #693: Pwning Ninja Hacker Academy – Part 3
    2025/09/19

    This week your pal and mine Joe “The Machine” Skeen kept picking away at pwning Ninja Hacker Academy. To review where we’ve been in parts 1 and 2:

    • We found a SQL injection on a box called SQL, got a privileged Sliver beacon on it, and dumped mimikatz info
    • From that dump, we used the SQL box hash to do a BloodHound run, which revealed that we had excessive permissions over the Computers OU
    • We useddacledit.py to give ourselves too much permission on the Computers OU

    Today we:

    • Did an RBCD attack against the WEB box
    • Requested a service ticket to give us local admin superpowers on WEB
    • Performed a secretsdump against WEB
    • Struggled to do a mimikatz dump at the end of the episode (after we ended the stream I realized I could’ve just done the mimikatz dump because I had local admin access! Oh well, we’ll pick things up again during part 4 next month!)
    続きを読む 一部表示
    29 分
まだレビューはありません