{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"7MS #737: Tales of Pentest Pwnage \u2013 Part 88","description":"Hello friends! Today\u2019s tale of pentest pwnage isn\u2019t a start-to-finish march to DA \u2013 it\u2019s me finally emptying out the backlog of \u201cgosh, I\u2019ve&amp;nbsp;got&amp;nbsp;to share this next time\u201d internal network tips that have been rattling around in my head. Here\u2019s what we get into:  Don\u2019t skip the boring stuff.&amp;nbsp;Even when I\u2019m testing the same network for the third or fourth time, I\u2019ve got an ever-growing list of things I check&amp;nbsp;every&amp;nbsp;single time \u2013 because config drift has a nasty habit of quietly reintroducing problems that were fixed years ago. Get a second opinion on your tools.&amp;nbsp;Lately I\u2019ve had BloodHound tell me a network is squeaky clean, and then gone and checked manually only to find the exact opposite sprawled all over the place. I don\u2019t know how to account for it, but it\u2019s changed how I work. (If you know the source of truth here, please write in!) Ghost machines.&amp;nbsp;That innocent little checkbox in Active Directory that turns a computer object into a gift-wrapped present for an attacker. We keep finding these in environments that had zero of them last year \u2013 and I share the two-pass trick that shakes even more of them loose. The weekend freebie.&amp;nbsp;Why I like to get my box lit up on a Friday even when the test doesn\u2019t officially start until Monday, and what tends to come wandering into my capture over 48 quiet hours. SNMP sweeps.&amp;nbsp;I\u2019ve&amp;nbsp;never&amp;nbsp;been caught doing one, and yet they\u2019ll happily hand over the make, model and firmware of some firewalls, switches and storage systems in the building. I think this finding deserves way more attention than it gets. (There are a few little commandlets waiting for you over at&amp;nbsp;7MinSec.wiki.) Be a consultant, not a Terminator 1000.&amp;nbsp;Why I run certain checks even when I\u2019m 99% sure I\u2019ll find nothing, why \u201cyou don\u2019t have this thing at all\u201d belongs in the accolades section, and how that one habit has led to some of the most appreciated conversations we\u2019ve had in report delivery meetings. Tangent department:&amp;nbsp;the dumb-but-glorious AI project that gave me the giggidies \u2013 a fully automated lobby bot for a Steam game that is absolutely, positively&amp;nbsp;not&amp;nbsp;for the kiddos. Also: the one line I won\u2019t cross with it, no matter how much my buddy eggs me on.  Got a tip of your own I should be adding to the \u201calways check this\u201d list? I\u2019d love to hear it! 7MinSec.com&amp;nbsp;for security services and show notes |&amp;nbsp;7MinSec.club&amp;nbsp;for our Substack and weekly TuesdayTOOLSdays |&amp;nbsp;7MinSec.wiki for pentesting tips, scripts and cheat sheets ","author_name":"7 Minute Security","author_url":"https:\/\/7MinSec.com","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/42591280\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/42591280"}