7MS #364: Tales of External Pentest Pwnage
May 23, 2019 • 36 minutes
This episode of the 7 Minute Security Podcast is brought to you by Authentic8, creators of Silo. Silo allows its users to conduct online investigations to collect information off the web securely and anonymously. For more information, check out Authentic8.
This episode features cool things I'm learning about external pentesting. But first, some updates:
My talk at Secure360 went really well. Only slightly #awkward thing is I felt an overwhelming need to change my title slide to talk about the fact that I don't drink.
The 7MS User Group went well. We'll resume in the late summer or early fall and do a session on lockpicking!
On the external pentest front, here are some items we cover in today's show:
MailSniper's Invoke-DomainHarvestOWA helps you discover the FQDN of your mail server target. Invoke-UsernameHarvestOWA helps you figure out what username scheme your target is using. Invoke-PasswordSprayOWA helps you do a low and slow password spray to hopefully find some creds!
Once inside the network, CrackMapExec is your friend. You can figure out where your compromised creds are valid across the network with this syntax:
crackmapexec smb 192.168.0.0/24 -u USER -p ‘PASSWORD’ -d YOURDOMAIN
You can also find what shares you have access to with:
crackmapexec smb 192.168.0.0/24 -u USER -p ‘PASSWORD’ -d YOURDOMAIN --shares
Sift through those shares! They often have VERY delicious bits of information in them :-)
Choose from the options below to listen and subscribe to 7 Minute Security in your podcast app of choice. By subscribing you will receive new episodes automatically.
Search for 7 Minute Security or copy the URL below and enter it in your podcast application.