Episodios

  • 7MS #625: A Peek into the 7MS Mail Bag - Part 4
    May 24 2024

    Road trip time! I’ve been traveling this week doing some fun security projects, and thought all this highway time would be a perfect opportunity to take a dip into the 7MS mail bag! Today’s questions include:

    • How do you price internal network penetration tests?
    • Have you ever had to deal with a difficult client situation, and how did you resolve it?
    • Are you done going after certs? Spoiler: no – I’m interested in doing the XINTRA labs (not sure if it includes a cert)
    • Do you provide managed services or just stick with more “one and done” assessment work?
    • You said the “smart business people” tell you to form reseller partnerships, otherwise you’re leaving money on the table – so why don’t you?
    • I’m thinking of starting my own cybersecurity consultancy – what type of insurance do I need to protect me in case of a digital “oops?”
    Más Menos
    44 m
  • 7MS #624: Tales of Pentest Pwnage – Part 57
    May 17 2024

    Today’s tale of pentest pwnage is all about my new favorite attack called SPN-less RBCD. We did a teaser episode last week that actually ended up being a full episode all about the attack, and even step by step commands to pull it off. But I didn’t want today’s episode to just be “Hey friends, check out the YouTube version of this attack!” so I also cover:

    • Our first first impressions of Burp Enterprise
    • Why I have a real hard time believing you have to follow all these steps to install Kali on Proxmox
    Más Menos
    29 m
  • 7MS #623: Prelude to a Tale of Pentest Pwnage
    May 10 2024

    Today’s prelude to a tale of pentest pwnage talks about something called “spnless RBCD” (resource-based constrained delegation). The show notes don't format well here in the podcast notes, so head to 7minsec.com to see the notes in all their glory.

    Más Menos
    25 m
  • 7MS #622: Migrating from vCenter to Proxmox - Part 1
    May 5 2024

    Sadly, the Broadcom acquisition of VMWare has hit 7MinSec hard – we love running ESXi on our NUCs, but ESXi free is no longer available. To add insult to injury, our vCenter lab at OVHcloud HQ got a huge price gouge (due to license cost increase; not OVH’s fault). Now we’re exploring Proxmox as an alternative hypervisor, so we’re using today’s episode to kick off a series about the joys and pains of this migration process.

    Más Menos
    17 m
  • 7MS #621: Eating the Security Dog Food - Part 6
    Apr 26 2024

    Today we revisit a series about eating the security dog food – in other words, practicing what we preach as security gurus! Specifically we talk about:

    • We’re going to get a third-party assessment on 7MinSec (the business)
    • Tips for secure email backup/storage
    • Limiting the retention of sensitive data you store in cloud places
    Más Menos
    24 m
  • 7MS #620: Securing Your Mental Health - Part 5
    Apr 21 2024

    Today we’re talking about tips to deal with stress and anxiety:

    • It sounds basic, but take breaks – and take them in a different place (don’t just stay in the office and do more screen/doom-scrolling)
    • I’ve never gotten to a place in my workload where I go “Ahhh, all caught up!” so I should stop striving to hit that invisible goal.
    • Chiropractic and back massages have done wonders for the tightness in my neck and shoulders
    • For me, video games where you punch and kick things relieves stress as well (including a specific game that’s definitely not for kids!)
    Más Menos
    23 m
  • 7MS #619: Tales of Pentest Pwnage – Part 56
    Apr 14 2024

    We did something crazy today and recorded an episode that was 7 minutes long! Today we talk about some things that have helped us out in recent pentests:

    • When using Farmer to create “trap” files that coerce authentication, I’ve found way better results using Windows Search Connectors (.searchConnector-ms) files
    • This matrix of “can I relay this to that” has been super helpful, especially early in engagements
    Más Menos
    7 m
  • 7MS #618: Writing Savage Pentest Reports with Sysreptor
    Apr 5 2024

    Today’s episode is all about writing reports in Sysreptor. It’s awesome! Main takeaways:

    • The price is free (they have a paid version as well)!
    • You can send findings and artifacts directly to the report server using the reptor Python module
    • Warning: Sysreptor only exports to PDF (no Word version option!)
    • Sysreptor has helped us write reports faster without sacrificing quality
    Más Menos
    39 m