7 Minute Security
Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I’m absolutely going to say it was intentional and that I totally meant to do that. Here’s what we cover: A client that’s actually doing the things – year two or three of testing this environment, and they had buttoned up so much that I had to dig deep. Great for them, freaking frustrating for me. Why my...
info_outline7 Minute Security
Hey friends! Today I’m talking about Baby’s First Neo — and to be crystal clear, I don’t mean Keanu, and I don’t mean the R&B guy with the hat. I mean the AI-powered pentest assistant from our pals at . Also to be crystal clear: this is not a sponsorship, ad, partnership or anything of the sort. Just me sharing a thing I like so you can decide if you like it too. Here’s what we get into: Why I didn’t renew my ProjectDiscovery cloud subscription after a full year of running it side-by-side with Nessus — including the three things that ground my...
info_outline7 Minute Security
Hello friends! Today’s tale of pentest pwnage isn’t a start-to-finish march to DA – it’s me finally emptying out the backlog of “gosh, I’ve got to share this next time” internal network tips that have been rattling around in my head. Here’s what we get into: Don’t skip the boring stuff. Even when I’m testing the same network for the third or fourth time, I’ve got an ever-growing list of things I check every single time – because config drift has a nasty habit of quietly reintroducing problems that were fixed years ago. Get a second opinion on...
info_outline7 Minute Security
Hey friends! Today’s another slice of our Securing Your Family During and After a Disaster miniseries, and fair warning — it’s a bit of a Friday mood-ruiner. It’s been almost two months since my dad passed, and we’ve moved into a phase nobody prepared me for. Here’s what we get into: The paperwork nobody thinks about — my mom still doesn’t know what her monthly income looks like now, and the answer is buried in a box somebody lost the key to. Divvying up a lifetime of stuff — and why our 2019 house fire completely rewired how I think about possessions....
info_outline7 Minute Security
Hey friends! Today’s episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a big audition and I was minutes away from finding out whether we were doing tears of joy or tears of sadness. Baby’s first Cloudflare Tunnel Not a sponsor, not an ad – just a thing I’d heard about for years and finally had a reason to use. Here’s what we get into: The problem that sent me down this road: I wanted push-button status pages for clients that pull from one source...
info_outline7 Minute Security
Hey friends! Today’s episode is a two-parter: some security stuff up front, and then a big ol’ personal celebration on the back half. If you’re strictly here for the security bits, I love you and you’re free to bail after the first half. If you’re here for both, God bless you. Part 1: Kicking the tires on Insight Recon What it is: is an Active Directory security assessment tool out of Heath Adams’ new venture, . I signed up for early access a while back, finally got a login, and took it for a spin this week in my lab. Not a sponsor, not an ad — just a...
info_outline7 Minute Security
Hey friends! Today’s episode comes to you from a parking lot in the rain, with a mint hot cocoa in hand and your host absolutely dragging his butt (D-R-A-G-G-I-N-G, not D-R-A-G-O-N – I’ve never seen a dragon’s butt and can’t speak to how mine compares). I’ve had a bunch of internals back to back lately and I’m basically a drooling dog who found a frisbee and refuses to put it down. Sleep be darned. So instead of walking through one test start to finish, I want to share a few things that have helped me claw out a foothold in environments that are otherwise really locked...
info_outline7 Minute Security
Hey friends! Welcome back to another Tales of Pentest Pwnage — my favorite mini-series where I share the good, the bad, and the “why didn’t I check THAT first?!” moments from real-world engagements. Today’s story has a little bit of everything: a legit path to domain admin, some late-night rabbit holes, a lesson in humility, and a villain you’ve definitely met before. (Spoiler: it’s DNS.) A couple of quick plugs before we dive in: Private GOAD training is going strong! — We just wrapped a 3-day private session (7 students — that’s max capacity!) of our Active...
info_outline7 Minute Security
Hey friends! Fair warning: today’s episode is a bit of an emotional rollercoaster — we’ve got a big security win, some honest lab feedback, and a very personal share about my dad’s funeral. Buckle up. certified, baby! — I’m officially a , courtesy of the folks at . It’s been a long time coming (I originally signed up for the live version and fell off after missing a couple Saturdays), but I came back for the self-paced 30-day version and finally finished the job. The lab experience — the good: — ~25 objectives, a solid lab guide, and a really fun...
info_outline7 Minute Security
Hey friends! Still your grieving pal over here, but also your swarming friend and Protecting My Network Edge host — because this week I’ve been tinkering with something called and I’ve got my diapers on regarding it, but I really, really like what I see so far. Then, fair warning, I flip on the tangent light and verbally barf up some personal stuff at the end. I’ll make the hand-off super clear, so if you want your free security podcast to do exactly what you want and nothing else — totally fair, and you won’t offend me by hopping off. Here’s what we cover: ...
info_outlineHey friends! Today’s episode comes to you from a parking lot in the rain, with a mint hot cocoa in hand and your host absolutely dragging his butt (D-R-A-G-G-I-N-G, not D-R-A-G-O-N – I’ve never seen a dragon’s butt and can’t speak to how mine compares). I’ve had a bunch of internals back to back lately and I’m basically a drooling dog who found a frisbee and refuses to put it down. Sleep be darned.
So instead of walking through one test start to finish, I want to share a few things that have helped me claw out a foothold in environments that are otherwise really locked down:
- The “good problem” of a mature client – several of these engagements are third- or fourth-year tests, and the clients actually clear findings off the board. Which is great for them and rough for me, because this year’s test shouldn’t look anything like last year’s.
- All my favorite go-tos came up empty – machine account quota set to zero, no broadcast traffic tomfoolery (Responder and mitm6 got me nothing), SMB signing on everywhere, ADCS either absent or buttoned up, and a low-priv account that BloodHound says has zero interesting permissions and zero local admin anywhere. Cool cool cool.
- When the network’s clean, go file-hunting – which means firing up Snaffler and letting it comb the shares. Normally that wraps up in about an hour. On these engagements it was running three and four hours.
- Then Windows told me I was out of disk – I like having Snaffler pull down copies of interesting files so I can review them locally instead of authenticating to each share. Turns out it had grabbed 50-60 gigs and left me with about eight gigs of breathing room.
- Tip #1: put a 1 TB drive in your drop boxes – I ran with tiny drives for years early in the 7MS days and it was always a pinch. Beyond situations like this one, sometimes you find a giant backup file or VMDK on a share and you need somewhere to put it so you can crack it open and go shopping.
- Tip #2: you can grow a VM disk on the fly – in Proxmox you can resize the disk on a running VM, then hop into Disk Management inside Windows and extend the C drive. Instant elbow room, no downtime.
- Death by a million tiny files – the real culprit was one file extension I should have excluded, and the client had hundreds of thousands of them. Rather than restart a run I was already hours into, I had AI whip up a little PowerShell loop that swept the Snaffler dump folder every 10 minutes and deleted the extensions I didn’t care about. Woke up the next morning to a finished run and plenty of free space.
- Making a gig-sized log file readable – I fed the log into Chimas, a slick web interface for Snaffler output that lets you filter down to just the red stuff or just the likely-credential files, and sort by modified date.
- Watch those timestamps – I kept finding AD creds in documents, then comparing the doc’s date against the account’s last password reset in BloodHound and discovering the file was a year stale. Son of a biscuit.
- The tool that actually cracked it open: Copernic Desktop Search – my pal Jeff McJunkin recommended this to me years ago, I talked about it on the show once, and then inexplicably forgot about it. Not a sponsor, no kickbacks, just a paid tool that’s earned its keep. It’s basically Google for your hard drive.
- How I use it – install it on the Windows VM, clear out the default indexing scope entirely, and point it only at the Snaffler dump folder. The top tier (about a hundred bucks a year) will chew through PSTs, DWGs, Office docs, PDFs and more, and it OCRs images too. Indexing took the better part of a day on these engagements, but then search is instant, and it previews basically every file type without Office installed. Years ago this same tool surfaced a photo on a file share of a piece of printer paper where a sysadmin had handwritten a 40-character admin password in Bic pen. OCR for the win.
- What I search for – the obvious stuff like “password,” plus the domain name, “plain text,” and things like “=sa” to sniff out SQL admin creds.
- Nuggets and threads to pull – sometimes a hit is the gold. Other times it just tells you where to go dumpster-diving like a raccoon on the live share. That’s how I found upgrade project plans with multiple teams and contractors involved, half-cleaned-up temp work, and high-privilege system, database and local admin creds just sitting there.
- Worth the hours – these didn’t all end in domain admin, but they were rich, real findings, and a great teaching opportunity about what’s sitting wide open to Domain Users. (Bonus: Copernic can also point straight at a UNC path with your AD creds and index it live.)
- Know a free alternative? – one of my favorite parts of doing this podcast is when someone writes in with “hey, there’s an open source thing that does that.” If that’s you, I’d love to hear it!
Also, on this week’s TuesdayTOOLSday I walked through getting a self-hosted Bitwarden password vault (and file sender) up and running on Linux, and there’s now a cheat sheet over at 7MinSec.wiki that’ll get you there in about seven minutes – all the commands from the official install guide in one place, with a couple of gotchas flagged.
Last thing: subscriptions to 7MinSec.club are free, but paid subs help cover hosting and the time this takes each week, and they’re getting some exclusive content soon. No guilt trip here, Mom – I’m going to keep barfing up everything I learn either way. But if you’ve got the means, I’d sure appreciate it.