Brian Johnson
7 Minute Security
7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
7MS #605: Navigating the Demands of Tech Leadership with Amanda Berlin of Blumira 05.01.2024 58:01
Today our friend Amanda Berlin , Lead Incident Detection Engineer at Blumira , joins us to talk about being more mentally healthy in 2024! P.S. - did you miss Amanda's past visits to the program? Then check out episode 518 , 536 and 588 . Be sure to check out the next edition of Amanda's Defensive Security Handbook when it comes out in later January, 2024!
7MS #604: A Two Tool Teaser 02.01.2024 26:04
Today we tease two upcoming tool releases (shooting for Q1, 2024): TCMLobbyBBQ - a Python script for PC players of The Texas Chain Saw Massacre game to help players get out of lobbies and into live games ASAP! The script uses PyAutoGUI to take screenshots of what part of the game you're in, then make appropriate key presses and mouse clicks to get into lobby queues, then alert you when the ga...
7MS #603: Monitoring Your Tailscale Network with Uptime Kuma 24.12.2023 28:22
Today I look at potentially replacing Splashtop and UptimeRobot (check out our episode about it here ) with Tailscale and Uptime Kuma . The missing link (which I'd love some help with) is answering this security question: how can I setup Tailscale so that my 7MinSec testing box can connect to all these NUCs spread around the globe, but those NUCs cannot connect to each other (in case one...
7MS #602: How to Succeed in Business Without Really Crying - Part 14 15.12.2023 44:35
Today we're talkin' business! Specifically: How to (gently) say "no" to (some) client projects How to (politely) challenge end-of-year deadlines An idea I'm kicking around in the lab - where I might do away with UptimeRobot and Splashtop in favor of Tailscale and Uptime Kuma
7MS #601: Breaking Up With Active Directory 11.12.2023 27:54
Today our pal Nate Schmitt (you may remember him from his excellent Dealing with Rejection: A DMARC Discussion Webinar) joins us to talk about breaking up with Active Directory. He covers: Why would you want to consider removing AD from your environment? What are common items to plan for? What steps should you take to efficiently plan a migration? What common challenges or considerations will yo...
7MS #600: First Impressions of Using AI on Penetration Tests 01.12.2023 22:39
Hey friends, today I share my experience working with ChatGPT, Ollama.ai , PentestGPT and privateGPT to help me pentest Active Directory, as well as a machine called Pilgrimage from HackTheBox . Will AI replace pentesters as we know them today? In my humble opinion: not quite yet. Check out today's episode to hear more, and please join me on Wednesday, December 6 for my Webinar on this topic...
7MS #599: Baby's First Responsible Disclosure 25.11.2023 38:36
Today we talk about our first experience working through the responsible disclosure process after finding vulnerabilities in a security product. We cannot share a whole lot of details as of right now, but wanted to give you some insight into the testing/reporting process thus far, which includes the use of: BulletsPassView MITMsmtp mitmproxy
7MS #598: Hacking Billy Madison - Part 4 17.11.2023 24:43
Today our good buddy Paul and I keep trying to hack the VulnHub machine based on the movie Billy Madison (see part 1 and 2 and 3 ). In today's final chapter, Paul and I: Find Eric's secret SSH back door Locate and decrypt a hidden file with Billy's homework Build wordlists with cewl Save Billy from the evil clutches of Eric Gordon!!!
7MS #597: Let's JAMBOREE (Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy) with Robert McCurdy 11.11.2023 32:40
Today we had a blast talking with Robert McCurdy about JAMBOREE (Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy) ! JAMBOREE allows you to quickly spin up a portable Git/Python/Java environment and much more! From a pentesting POV, you can whip up an Android pentesting environment, BloodHound/SharpHound combo, Burp Suite...the list goes on!
7MS #596: How to Succeed in Business Without Really Crying - Part 13 04.11.2023 31:07
After about a year break ( last edition of this series was in October, 2022 , we're back with an updated episode of How to Succeed in Business Without Really Crying. We cover: Why we're not planning on selling the business any time soon Fast Google Dorks Scan Using ProtonVPN via command line Our pre first impressions of a pentesting SaaS tool you've almost definitely heard of
7MS #595: Choosing the Right XDR Strategy with Matt Warner of Blumira 31.10.2023 1:03:09
Today we're joined by Matt Warner of Blumira (remember him from episodes #551 and #529 and #507 ?) to talk about choosing the right XDR strategy! There's a lot to unpack here. Are EDR, MDR and XDR related? Can you get them all from one vendor - and should you? Do you run them on-prem, in the cloud, or both? Join us as Matt answers these questions and more!
7MS #594: Using PatchMyPC to Auto-Update Pentest Dropboxes 23.10.2023 29:49
Today we're talking about how you can use PatchMyPc to keep your home PC and/or pentest dropbox automatically updated with the latest/greatest patches!
7MS #593: Hacking Billy Madison - Part 3 15.10.2023 38:56
Hey friends, today my Paul and I kept trying to hack the VulnHub machine based on the movie Billy Madison (see part 1 and 2 ). In our journey we learned some good stuff: Port knocking is awesome using utilities like knock : /opt/knock/knock 10.0.7.124 1466 67 1469 1514 1981 1986 Sending emails via command line is made (fairly) easy with swaks: swaks --to eric@madisonhotels.com --from vva...
7MS #592: 7 Steps to Recover Your Hacked Facebook Account 06.10.2023 19:42
Today we're talking about 7 steps you can take to (hopefully) reclaim a hacked Facebook account. The key steps are: Ask Facebook for help (good luck with that) Put out an SOS on your socials Flag down the FBI Call the cops! Grumble to your attorney general Have patience Lock it down (once you get the account back)! Also, I have to say that this article was a fantastic resource in helping me cr...
7MS #591: Tales of Pentest Pwnage - Part 52 29.09.2023 33:39
Today we talk about an awesome path to internal network pentest pwnage using downgraded authentication from a domain controller, a tool called ntlmv1-multi , and a boatload of cloud-cracking power on the cheap from vast.ai . Here's my chicken scratch notes for how to take the downgraded authentication hash capture (using Responder.py -I eth0 --lm ) and eventually tweeze out the NTLM hash of t...
7MS #590: Hacking Billy Madison - Part 2 22.09.2023 13:40
Today my Paul and I continued hacking Billy Madison (see part one here ) and learned some interesting things: You can fuzz a URL with a specific file type using a format like this: wfuzz -c -z file,/root/Desktop/wordlist.txt --hc 404 http://x.x.x.x/FUZZ.cap To rip .cap files apart and make them "pretty" you can use tpick : tcpick -C -yP -r tcp_dump.pcap Or tcpflow: apt install tcpflow tcpflo...
7MS #589: Tales of Pentest Pwnage - Part 51 15.09.2023 14:42
In today's tale of pentest pwnage we talk about: The importance of local admin and how access to even one server might mean instant, full control over their backup or virtualization infrastructure Copying files via WinRM when copying over SMB is blocked: $sess = New-PSSession -Computername SERVER-I-HAVE-LOCAL-ADMIN-ACCESS-ON -Credential * ...then provide your creds...and then: copy-item c:\super...
7MS #588: Becoming a Sysmon Sensei with Amanda Berlin 08.09.2023 24:40
Today Amanda Berlin from Blumira teaches us how to unlock the power of Sysmon so we can gain insight into the good, bad and ugly things happening on our corporate endpoints! Key takeaways: Sysmon turns your windows logging up to 11, and pairs well with a config file like this one or this one . Careful if you are are running sysmon on non-SSD drives - the intense number of writes might bring...
7MS #587: Hacking Billy Madison 01.09.2023 36:51
Today my pal Paul from Project7 and I hack the heck out of Billy Madison a vulnerable virtual machine that is celebrating its 7th anniversary this month!
7MS #586: DIY Pentest Dropbox Tips – Part 8 25.08.2023 18:51
Today, sadly, might be the last episode of DIY pentest dropbox tips for a while because I found (well, ChatGPT did actually) the missing link to 100% automate a Kali Linux install! Check episode #449 for more info on building your Kali preseed file, but essentially the last line in my file runs a kali.sh script to download/install all the pentest tools I want. The "missing link" part is I figu...
7MS #585: DIY Pentest Dropbox Tips – Part 7 18.08.2023 24:01
Hey friends, today I'm super excited to share I found the missing link! Specifically, the missing piece that now allows me to create fully automated Windows 10 installs that serve as virtual pentest jumpboxes. Here are the high points: When your deployment script is finishing and you need the system to reboot and run some final commands, temporarily add your account as an auto-login account like...
7MS #584: Tales of Pentest Pwnage - Part 50 11.08.2023 17:36
In today's tale of pwnage, we'll talk about how domain trusts can be dangerous because they have...well...trust issues.
7MS #583: Cred-Capturing Phishing with Caddy Server 04.08.2023 29:37
Today we talk about crafting cool cred-capturing phishing campaigns with Caddy server ! Here's a quick set of install commands for Ubuntu: sudo apt install -y debian-keyring debian-archive-keyring apt-transport-https curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' | sudo gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg curl -1sLf 'https://dl.cloudsmith.io/pu...
7MS #582: Using Wazuh as a SIEM for Work and Home 31.07.2023 50:48
Today we had a blast playing with Wazuh as a SIEM you can use for work and/or home. Inspiration for this episode came from Network Chuck . This one-liner will literally get Wazuh installed in about 5 minutes: curl -sO https://packages.wazuh.com/4.4/wazuh-install.sh && sudo bash ./wazuh-install.sh -a P.S. if you accidentally close your command window before writing down the admin password (like...
7MS #581: Tales of Pentest Pwnage - Part 49 21.07.2023 22:40
Oooo, giggidy! Today's tale of pentest pwnage is about pwning vCenter with CVE-2021-44228 - a vulnerability that lets us bypass authentication entirely and do/take what we want from vCenter! Key links to make the magic happen: How to exploit log4j manually in vCenter How to automate the attack! Tool to steal the SAML database you extract from vCenter
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.