{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"7MS #733: Tales of Pentest Pwnage \u2013 Part 87","description":"Hey friends! Today\u2019s episode comes to you from a parking lot in the rain, with a mint hot cocoa in hand and your host absolutely dragging his butt (D-R-A-G-G-I-N-G, not D-R-A-G-O-N \u2013 I\u2019ve never seen a dragon\u2019s butt and can\u2019t speak to how mine compares). I\u2019ve had a bunch of internals back to back lately and I\u2019m basically a drooling dog who found a frisbee and refuses to put it down. Sleep be darned. So instead of walking through one test start to finish, I want to share a few things that have helped me claw out a foothold in environments that are otherwise&amp;nbsp;really&amp;nbsp;locked down:  The \u201cgood problem\u201d of a mature client&amp;nbsp;\u2013 several of these engagements are third- or fourth-year tests, and the clients actually clear findings off the board. Which is great for them and rough for me, because this year\u2019s test shouldn\u2019t look anything like last year\u2019s. All my favorite go-tos came up empty&amp;nbsp;\u2013 machine account quota set to zero, no broadcast traffic tomfoolery (Responder&amp;nbsp;and mitm6 got me nothing), SMB signing on everywhere, ADCS either absent or buttoned up, and a low-priv account that&amp;nbsp;BloodHound&amp;nbsp;says has zero interesting permissions and zero local admin anywhere. Cool cool cool. When the network\u2019s clean, go file-hunting&amp;nbsp;\u2013 which means firing up&amp;nbsp;Snaffler&amp;nbsp;and letting it comb the shares. Normally that wraps up in about an hour. On these engagements it was running three and four hours. Then Windows told me I was out of disk&amp;nbsp;\u2013 I like having Snaffler pull down copies of interesting files so I can review them locally instead of authenticating to each share. Turns out it had grabbed 50-60 gigs and left me with about eight gigs of breathing room. Tip #1: put a 1 TB drive in your drop boxes&amp;nbsp;\u2013 I ran with tiny drives for years early in the 7MS days and it was always a pinch. Beyond situations like this one, sometimes you find a giant backup file or VMDK on a share and you need somewhere to put it so you can crack it open and go shopping. Tip #2: you can grow a VM disk on the fly&amp;nbsp;\u2013 in Proxmox you can resize the disk on a running VM, then hop into Disk Management inside Windows and extend the C drive. Instant elbow room, no downtime. Death by a million tiny files&amp;nbsp;\u2013 the real culprit was one file extension I&amp;nbsp;should&amp;nbsp;have excluded, and the client had hundreds of thousands of them. Rather than restart a run I was already hours into, I had AI whip up a little PowerShell loop that swept the Snaffler dump folder every 10 minutes and deleted the extensions I didn\u2019t care about. Woke up the next morning to a finished run and plenty of free space. Making a gig-sized log file readable&amp;nbsp;\u2013 I fed the log into&amp;nbsp;Chimas, a slick web interface for Snaffler output that lets you filter down to just the red stuff or just the likely-credential files, and sort by modified date. Watch those timestamps&amp;nbsp;\u2013 I kept finding AD creds in documents, then comparing the doc\u2019s date against the account\u2019s last password reset in BloodHound and discovering the file was a year stale. Son of a biscuit. The tool that actually cracked it open:&amp;nbsp;Copernic Desktop Search&amp;nbsp;\u2013 my pal Jeff McJunkin recommended this to me years ago, I talked about it on the show once, and then inexplicably forgot about it. Not a sponsor, no kickbacks, just a paid tool that\u2019s earned its keep. It\u2019s basically Google for your hard drive. How I use it&amp;nbsp;\u2013 install it on the Windows VM, clear out the default indexing scope entirely, and point it only at the Snaffler dump folder. The top tier (about a hundred bucks a year) will chew through PSTs, DWGs, Office docs, PDFs and more, and it OCRs images too. Indexing took the better part of a day on these engagements, but then search is instant, and it previews basically every file type without Office installed.&amp;nbsp; Years ago this same tool surfaced a photo on a file share of a piece of printer paper where a sysadmin had handwritten a 40-character admin password in Bic pen. OCR for the win. What I search for&amp;nbsp;\u2013 the obvious stuff like \u201cpassword,\u201d plus the domain name, \u201cplain text,\u201d and things like \u201c=sa\u201d to sniff out SQL admin creds. Nuggets and threads to pull&amp;nbsp;\u2013 sometimes a hit&amp;nbsp;is&amp;nbsp;the gold. Other times it just tells you where to go dumpster-diving like a raccoon on the live share. That\u2019s how I found upgrade project plans with multiple teams and contractors involved, half-cleaned-up temp work, and high-privilege system, database and local admin creds just sitting there. Worth the hours&amp;nbsp;\u2013 these didn\u2019t all end in domain admin, but they were rich, real findings, and a great teaching opportunity about what\u2019s sitting wide open to Domain Users. (Bonus: Copernic can also point straight at a UNC path with your AD creds and index it live.) Know a free alternative?&amp;nbsp;\u2013 one of my favorite parts of doing this podcast is when someone writes in with \u201chey, there\u2019s an open source thing that does that.\u201d If that\u2019s you, I\u2019d love to hear it!  Also, on this week\u2019s&amp;nbsp;TuesdayTOOLSday&amp;nbsp;I walked through getting a self-hosted Bitwarden password vault (and file sender) up and running on Linux, and there\u2019s now a cheat sheet over at&amp;nbsp;7MinSec.wiki&amp;nbsp;that\u2019ll get you there in about seven minutes \u2013 all the commands from the official install guide in one place, with a couple of gotchas flagged. Last thing: subscriptions to&amp;nbsp;7MinSec.club are free, but paid subs help cover hosting and the time this takes each week, and they\u2019re getting some exclusive content soon. No guilt trip here, Mom \u2013 I\u2019m going to keep barfing up everything I learn either way. But if you\u2019ve got the means, I\u2019d sure appreciate it. ","author_name":"7 Minute Security","author_url":"https:\/\/7MinSec.com","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/42278110\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/42278110"}