Tradecraft Security Weekly (Video)

Tradecraft Security Weekly (Video)

By Security WeeklyTechnology
Download on the App Store

Tradecraft Security Weekly (Video) episodes

  • Command & Control 101: Transports - Tradecraft Security Weekly #9

    After an attacker is successful in getting a payload onto a system and getting it to run they still have to worry about whether there will be a successful connection out to a command and control server. There are a number of different transport mechanisms that can be utilized including direct TCP connections, pivoting through a proxy, DNS, or even ICMP to name a few. In this episode of Tradecraft Security Weekly Beau Bullock (@dafthack) details some of these transports that can be used to establish remote command and control over a system.

    LINKS:

    Dnscat - https://github.com/iagox86/dnscat2

    Gcat - https://github.com/byt3bl33d3r/gcat

    PowerShellICMP - https://github.com/samratashok/nishang/blob/master/Shells/Invoke-PowerShellIcmp.ps1

    icmpsh - https://github.com/inquisb/icmpsh

    Week of PowerShell Shells - http://www.labofapenetrationtester.com/2015/05/week-of-powershell-shells-day-1.html

    12 min
  • OSINT & External Recon Pt. 1: Host Discovery - Tradecraft Security Weekly #8

    During the reconnaissance phase of a penetration test being able to discover the external assets of an organization is extremely important. It is also important to do so as stealthily as possible. Using open-source techniques and tools it is possible to enumerate an organizations external assets without sending any data directly from your computer system to the target organization's subnets. In this episode of Tradecraft Security Weekly Beau Bullock (@dafthack) discusses some of the tools and techniques that can be used to do this.

    LINKS: Recon-ng: https://bitbucket.org/LaNMaSteR53/recon-ng Datasploit: https://github.com/DataSploit/datasploit Spiderfoot: http://www.spiderfoot.net/ Censys: https://censys.io/ Shodan: https://www.shodan.io/ Threatcrowd: https://www.threatcrowd.org/ HackerTarget: https://hackertarget.com/ Netcraft: https://www.netcraft.com/

    Certificate Search Tool - crt.sh Internet-Wide Scan Data Repository - scans.io

    Full Show Notes: https://wiki.securityweekly.com/TS_Episode08

    13 min
  • Situational Awareness with HostRecon - Tradecraft Security Weekly #7

    After exploiting a system on a remote & unfamiliar network it is extremely important to gain situational awareness as quickly, and quietly as possible. This will help ensure success moving forward with other attacks. In this episode of Tradecraft Security Weekly Beau Bullock (@dafthack) will show how to use PowerShell to query information about the current computer, user, and domain to avoid running built-in commands like 'net', 'ipconfig', or 'netstat'.

    LINKS: HostRecon: https://github.com/dafthack/HostRecon More on HostRecon: https://www.blackhillsinfosec.com/?p=5824

    11 min
  • WordPress Vulnerability Discovery and Exploitation - Tradecraft Security Weekly #6

    Over 27% of all websites globally run WordPress. This makes WordPress a very highly targeted piece of software. There are numbers of different aspects to consider when attempting to discover vulnerabilities in WordPress. In this episode of Tradecraft Security Weekly Beau Bullock (@dafthack) discusses how to find vulnerabilities in WordPress sites and how to exploit them.

    LINKS: WordPress Security Guide - http://www.wpbeginner.com/wordpress-security/

    WordPress Vuln Database - www.wpvulndb.com

    WPScan- https://github.com/wpscanteam/wpscan

    WPSeku- https://github.com/m4ll0k/WPSeku

    14 min
  • Password Spraying Windows Active Directory Accounts - Tradecraft Security Weekly #5

    Compromising the credentials of users in an Active Directory environment can assist in providing new possibilities for pivoting around the network. It allows for additional access to various network resources like shares, email and other systems. In this week's episode of Tradecraft Security Weekly Beau Bullock (@dafthack) discusses how to perform password spraying attacks using the PowerShell tool DomainPasswordSpray, and also the Metasploit module smb_login.

    Links:

    DomainPasswordSpray - https://github.com/dafthack/DomainPasswordSpray

    Metasploit smb_login - https://www.rapid7.com/db/modules/auxiliary/scanner/smb/smb_login

    11 min
  • Meterpreter with Categorized Domains & Trusted Certs - Tradecraft Security Weekly #4

    It is common for organizations to proxy web traffic so they can place restrictions on what websites can be visited by employees. To make the management of allowing or denying access to a large number of sites easier many web proxies utilize categorization engines to group sites into various subjects. Uncategorized sites are generally blocked. In this episode I show how it's easy to locate recently expired domains that have been categorized already, and can be utilized to get past web proxy filters. Additionally, I show how easy it is to set up a trusted certificate on the payload handler to encrypt the session using a custom cert.

    Links: DomainHunter - https://github.com/minisllc/domainhunter

    Brian Fehrman Blog Post - http://www.blackhillsinfosec.com/?p=5831

    13 min
  • Attacking Exchange/OWA to Gain Access to AD Accounts - Tradecraft Security Weekly #3

    Microsoft Exchange and Office365 are extremely popular products that organizations use for enterprise email. These services can be exploited by remote attackers to potentially gain access to Active Directory user credentials. In this Tradecraft Security Weekly episode Beau Bullock (@dafthack) demonstrates how to utilize MailSniper to enumerate internal domains, enumerate usernames, perform password spraying attacks, and get the global address list from Exchange and Office365 portals.

    Links: MailSniper - https://github.com/dafthack/MailSniper

    13 min
  • Public File Metadata Analysis - Tradecraft Security Weekly #1

    Public File Metadata Analysis with PowerMeta - It is very common for organizations to post files (docx, pdf, xlsx, etc.) to publicly available websites on the Internet. Often times these organizations have not taken the time to strip the metadata attached to these files. This leaves the potential for remote attackers to discover sensitive information from them including usernames, software used to create them, or system names. In this episode Beau demonstrates a PowerShell tool called PowerMeta that can be used to discover these files on a target site and extract the metadata from them.

    PowerMeta: https://github.com/dafthack/PowerMeta

    Strip Word Docs of Metadata: https://support.office.com/en-us/article/Remove-hidden-data-and-personal-information-by-inspecting-documents-356b7b5d-77af-44fe-a07f-9aa4d085966f

    Strip PDFs of Metadata: https://blog.joshlemon.com.au/protecting-your-pdf-files-and-metadata/

    Strip Photos of Metadata: http://www.makeuseof.com/tag/3-ways-to-remove-exif-metadata-from-photos-and-why-you-might-want-to/

    12 min
  • Windows Privilege Escalation Techniques (Local) - Tradecraft Security Weekly #2

    In episode 2 of Tradecraft Security Weekly Beau Bullock (@dafthack) discusses Windows privilege escalation techniques. There are many reasons why normal employees should not be local administrators of their own systems. Network administrators tend to lock down permissions correctly for users, but privilege escalation vulnerabilities still arise through various software or system configuration. A few tools and techniques for discovering these vulnerabilities include PowerUp (by @harmj0y), Hot Potato (by foxglovesec), and manually finding exploits for missing MS patches with Searchsploit are discussed.

    Links:

    PowerUp by harmj0y: https://github.com/PowerShellMafia/PowerSploit/tree/master/Privesc Potato by foxglovesec: https://github.com/foxglovesec/Potato Tater (PowerShell Implementation of Hot Potato exploit): https://github.com/Kevin-Robertson/Tater SessionGopher: https://github.com/fireeye/SessionGopher

    12 min

About Tradecraft Security Weekly (Video)

From the publisher's feed

Want to learn about all of the latest security tools and techniques? This is the show for you! We show you how to install, configure and use a wide variety of security tools for both offense and…