Tradecraft Security Weekly (Video)

Tradecraft Security Weekly (Video)

By Security WeeklyTechnology
Download on the App Store

Tradecraft Security Weekly (Video) episodes

  • Dissecting XXE Attacks - Tradecraft Security Weekly #19

    When pentesting web services or an application that leverage XML files, XML External Entity (XXE) attacks are a great way to start. By injecting an XXE into a well crafted XML payload before it's sent to the server, a penetration tester can trick the parser into executing other actions that the developer never intended. This can lead to reading local files, server-side request forgeries (SSRF) or even gaining remote code execution (RCE). To help penetration testers, Beau Bullock (@dafthack) and Mike Felch (@ustayready) cover a few different methods to attack XML parsers in episode 19 of Tradecraft Security Weekly.

    Links: https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Prevention_Cheat_Sheet

    15 min
  • Domain Fronting - Tradecraft Security Weekly #18

    Domain fronting is a technique used to mask command and control (C2) traffic. It is possible for C2 channels to be proxied through CDN's like Cloudfront to make it appear like normal Internet traffic. It is very difficult to detect and block for defenders as it appears as if clients on a network are connecting to valid CDN domains. But, in reality it is transporting a command and control channel. In this episode of Tradecraft Security Weekly Beau Bullock (@dafthack) is joined by Ralph May (@ralphte1) to talk about what domain fronting is and how to set it up using Cloudfront and PowerShell Empire.

    Full Show Notes: https://wiki.securityweekly.com/TS_Episode18

    LINKS: https://blog.cobaltstrike.com/2017/02/06/high-reputation-redirectors-and-domain-fronting/ https://signal.org/blog/doodles-stickers-censorship/ https://www.securityartwork.es/2017/01/24/camouflage-at-encryption-layer-domain-fronting/ https://trac.torproject.org/projects/tor/wiki/doc/meek http://bryceboe.com/2012/03/12/bypassing-gogos-inflight-internet-authentication/

    16 min
  • Cracking Password Hashes Efficiently - Tradecraft Security Weekly #17

    If you are a penetration tester password cracking is something you will inevitably do. On most engagements we typically don't have months on end to crack passwords. In an effort to help be more efficient in your cracking techniques Beau Bullock (@dafthack) describes various ways to streamline your approach to cracking in episode 17 of Tradecraft Security Weekly.

    LINKS: Beau's blog post on password cracking - http://www.dafthack.com/blog/howtocrackpasswordhashesefficiently Hashcat Hash Examples - https://hashcat.net/wiki/doku.php?id=example_hashes

    16 min
  • Pivoting Tools Through Meterpreter - Tradecraft Security Weekly #16

    There are a ton of modules in Metasploit that are extremely useful for performing various attacks post-exploitation. But sometimes there are external tools that you might want to use that are not included in Metasploit. It's possible to proxy other external tools through a Meterpreter session using a module in Metasploit and proxychains. In this episode Derek Banks (@0xderuke) and Beau Bullock (@dafthack) talk about how to pivot external tools through Meterpreter sessions and demo how to dump Kerberos tickets using this method.

    LINKS:

    BHIS Toast to Kerberoast Blog - https://www.blackhillsinfosec.com/a-toast-to-kerberoast/

    12 min
  • Identifying Weak Session Tokens Using Entropy - Tradecraft Security Weekly #15

    Session management in web applications is extremely important in regards to securing user credentials and integrity within the application. Sometimes session tokens can be predicted provided the overall randomness is weak. If this is possible a remote attacker may be able to compromise the session of an authenticated user. In this episode of Tradecraft Security Weekly both Beau Bullock (@dafthack) and Mike Felch (@ustayready) discuss the issues associated with creating session tokens with weak entropy.

    14 min
  • Relaying NTLMv1/v2 - Tradecraft Security Weekly #14

    A very common attack that many networks are vulnerable to is called LLMNR or NBT-NS poisoning. Through this attack it is possible to gain access to a user's NTLMv1 or v2 password hash. A more interesting attack can be carried out under the same premise though. Instead of just obtaining a password hash the user's authenticated session to another host can be exploited to run arbitrary code on the server. In this episode of Tradecraft Security Weekly Beau Bullock (@dafthack) shows how to perform this attack using the PowerShell tool Inveigh.

    14 min
  • Black Hat & DEF CON 2017 - Tradecraft Security Weekly #13

    There were a lot of amazing new tools and techniques released at Hacker Summer Camp 2017. In this week's episode of Tradecraft Security Weekly Beau Bullock (@dafthack) talks about some of the more interesting items he saw at the Black Hat and DEF CON conferences.

    Full Show Notes: https://wiki.securityweekly.com/TS_Episode13

    LINKS:

    • Kali Linux Revealed - https://www.kali.org/download-kali-linux-revealed-book/
    • Spiderlabs Portia - https://github.com/SpiderLabs/portia
    • Duo isthislegit and phimm - https://duo.com/blog/new-open-source-phishing-tools-isthislegit-and-phinn
    • Revoke-obfuscation - https://www.fireeye.com/blog/threat-research/2017/07/revoke-obfuscation-powershell.html & https://github.com/danielbohannon/Revoke-Obfuscation
    • EAPHammer - https://github.com/s0lst1c3/eaphammer
    • Kwetza - https://github.com/sensepost/kwetza
    • Koadic - https://github.com/zerosum0x0/koadic
    • SRDI - https://github.com/monoxgas/sRDI
    • Yasuo - https://github.com/0xsauby/yasuo
    • Printer Exploit Kit - https://www.pcmag.com/news/355256/your-printer-can-steal-and-deface-your-documents & https://github.com/RUB-NDS/PRET
    12 min
  • Automating Screenshots to Quickly Assess Many WebApps - Tradecraft Security Weekly #12

    On penetration tests we are often-times faced with very large external or internal attack surfaces that are made up of multiple web applications. When there is a need to assess thousands of webapps quickly manually navigating each page with a browser would be very inefficient. In this episode of Tradecraft Security Weekly Beau Bullock (@dafthack) details how to automatically screenshot multiple web applications for quick analysis.

    Full Show Notes: https://wiki.securityweekly.com/TS_Episode12

    LINKS: EyeWitness - https://github.com/ChrisTruncer/EyeWitness Rawr - https://bitbucket.org/al14s/rawr/wiki/Home httpscreenshot - https://github.com/breenmachine/httpscreenshot Peeping Tom - https://bitbucket.org/LaNMaSteR53/peepingtom/ PowerWebShot - https://github.com/dafthack/PowerWebShot

    10 min
  • Sensitive Data Discovery in Email with MailSniper - Tradecraft Security Weekly #11

    Email tends to be the primary communication platform for employees of an organization. Often times sensitive data is transmitted from one internal employee to another via this mechanism with no regard for security. In this episode of Tradecraft Security Weekly Beau Bullock (@dafthack) shows how to use a PowerShell-based tool called MailSniper to search through the mailboxes of employees at an organization for sensitive data.

    LINKS: MailSniper - https://github.com/dafthack/MailSniper Office365

    Compliance Search - https://msitpros.com/?p=3678

    Full Show Notes: https://wiki.securityweekly.com/TS_Episode11

    12 min
  • Live Response with Google Rapid Response (Blue Team Edition) - Tradecraft Security Weekly #10

    How do you perform incident response on systems in your environment at scale or when the system that needs to be analyzed is in a geographically different location than your analysts? What if you need to do this and have no real budget to work with to use commercial tools? The answer is Google Rapid Response (Google GRR). In this Blue Team Edition Episode of Tradecraft Security Weekly we (@0xderuke & @dafthack) demonstrate retrieving a potentially weaponized spreadsheet from a remote computer system using GRR.

    LINKS: http://github.com/google/grr

    10 min

About Tradecraft Security Weekly (Video)

From the publisher's feed

Want to learn about all of the latest security tools and techniques? This is the show for you! We show you how to install, configure and use a wide variety of security tools for both offense and…