{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"7MS #724: Tales of Pentest Pwnage - Part 85","description":" Hey friends! Today we\u2019re going deep on external network pentesting \u2014 something I realize we\u2019ve barely touched in however many episodes we\u2019ve done. I\u2019m currently in a long stretch of back-to-back external assessments, so it felt like a good time to talk about it.  Here\u2019s what we get into:   Scoping headaches&amp;nbsp;\u2014 why the old \u201ccount your public IPs and multiply by a big hourly rate\u201d approach drives me crazy, and how we actually scope external tests to be fair to everyone  Web apps in scope or not?&amp;nbsp;\u2014 this needs its own conversation before the test starts, and skipping it causes pain later  Testing under real conditions&amp;nbsp;\u2014 the debate around whether to request an allowlist vs. scanning as-is, and why I lean toward creating the best testing environment possible  Multi-tool enumeration&amp;nbsp;\u2014 why we run Nessus, Project Discovery, and Shodan together, and what each catches that the others miss  Reporting the surface&amp;nbsp;\u2014 why just walking a customer through what\u2019s exposed to the internet (ports, services, screenshots) has more value than I used to give it credit for  SNMP and NTP findings&amp;nbsp;\u2014 two protocols that keep showing up open when they really (probably) shouldn\u2019t be  OSINT phase&amp;nbsp;\u2014 how we\u2019ve grown externals to include open-source intelligence work on the customer\u2019s domains, not just IP-level scanning  WordPress hygiene&amp;nbsp;\u2014 it keeps coming up on these assessments, and I\u2019ve got some practical recommendations  Dorking and metadata searches&amp;nbsp;\u2014 using AI to quickly sift through publicly exposed documents for things attackers could use to pretext a social engineering attack  Subdomain hijacking&amp;nbsp;\u2014 a sneaky attack path I\u2019ve seen in the wild that flies right in the face of all the \u201ccheck if the URL is spelled right\u201d advice we give users   Even when the technical findings are pretty quiet, there\u2019s a lot you can do to punch up an external pentest report with stuff that\u2019s genuinely valuable to customers! ","author_name":"7 Minute Security","author_url":"https:\/\/7MinSec.com","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/41465875\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/41465875"}