7MS #354: Tales of Internal Pentest Pwnage - Part 2 episode artwork

EPISODE · Mar 25, 2019 · 38 MIN

7MS #354: Tales of Internal Pentest Pwnage - Part 2

from 7 Minute Security · host Brian Johnson

Today's episode is the thrilling, exciting, heart-pounding conclusion of Tales of Internal Pentest Pwnage - Part 1. In this episode, we cover the final "wins" that got me to Domain Admin status (and beyond!): Got DA but can't get to your final "crown jewels" destinations? How about going after the organization's backups (evil grin!) Got DA but stuck to find hot leads to where the crown jewels are? Get snoopy and go through people's files, folders and...bookmark caches! (evil grin #2!) If your nmap/eyewitness scan turns up Web sites with simply an IIS default landing page or "It works!" Apache page on it, there's probably more there than meets the eye. We also talk about lessons learned from this pentest - both things done well and things the org can do to make the next pentester's job a lot harder.

Episode metadata supplied by the publisher feed · Published Mar 25, 2019

Embed this episode

NOW PLAYING

7MS #354: Tales of Internal Pentest Pwnage - Part 2

0:00 38:06

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of 7 Minute Security?

This episode is 38 minutes long.

When was this 7 Minute Security episode published?

This episode was published on March 25, 2019.

Can I download this 7 Minute Security episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!