7MS #724: Tales of Pentest Pwnage - Part 85

7MS #724: Tales of Pentest Pwnage - Part 85

Hey friends! Today we're going deep on external network pentesting — something I realize we've barely touched in however many episodes we've done. I'm currently in a long stretch of back-to-back external assessments, so it felt like a good time to talk about it.

Here's what we get into:

  • Scoping headaches — why the old "count your public IPs and multiply by a big hourly rate" approach drives me crazy, and how we actually scope external tests to be fair to everyone
  • Web apps in scope or not? — this needs its own conversation before the test starts, and skipping it causes pain later
  • Testing under real conditions — the debate around whether to request an allowlist vs. scanning as-is, and why I lean toward creating the best testing environment possible
  • Multi-tool enumeration — why we run Nessus, Project Discovery, and Shodan together, and what each catches that the others miss
  • Reporting the surface — why just walking a customer through what's exposed to the internet (ports, services, screenshots) has more value than I used to give it credit for
  • SNMP and NTP findings — two protocols that keep showing up open when they really (probably) shouldn't be
  • OSINT phase — how we've grown externals to include open-source intelligence work on the customer's domains, not just IP-level scanning
  • WordPress hygiene — it keeps coming up on these assessments, and I've got some practical recommendations
  • Dorking and metadata searches — using AI to quickly sift through publicly exposed documents for things attackers could use to pretext a social engineering attack
  • Subdomain hijacking — a sneaky attack path I've seen in the wild that flies right in the face of all the "check if the URL is spelled right" advice we give users

Even when the technical findings are pretty quiet, there's a lot you can do to punch up an external pentest report with stuff that's genuinely valuable to customers!

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(736)

7MS #736: Securing Your Family During and After a Disaster – Part 9

7MS #736: Securing Your Family During and After a Disaster – Part 9

Hey friends! Today's another slice of our Securing Your Family During and After a Disaster miniseries, and fair warning — it's a bit of a Friday mood-ruiner. It's been almost two months since my dad p...

21 Elo 29min

7MS #735: Baby's First Cloudflare Tunnel

7MS #735: Baby's First Cloudflare Tunnel

Hey friends! Today's episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a...

14 Elo 24min

7MS #734: Insight Recon

7MS #734: Insight Recon

Hey friends! Today's episode is a two-parter: some security stuff up front, and then a big ol' personal celebration on the back half. If you're strictly here for the security bits, I love you and you'...

7 Elo 32min

7MS #733: Tales of Pentest Pwnage – Part 87

7MS #733: Tales of Pentest Pwnage – Part 87

Hey friends! Today's episode comes to you from a parking lot in the rain, with a mint hot cocoa in hand and your host absolutely dragging his butt (D-R-A-G-G-I-N-G, not D-R-A-G-O-N – I've never seen a...

31 Heinä 23min

7MS #732: Tales of Pentest Pwnage – Part 86

7MS #732: Tales of Pentest Pwnage – Part 86

Hey friends! Welcome back to another Tales of Pentest Pwnage — my favorite mini-series where I share the good, the bad, and the "why didn't I check THAT first?!" moments from real-world engagements. T...

24 Heinä 40min

7MS #731: CARTP – Cloud Red Team Tactics for Attacking and Defending Azure – THE FINAL CHAPTER!

7MS #731: CARTP – Cloud Red Team Tactics for Attacking and Defending Azure – THE FINAL CHAPTER!

Hey friends! Fair warning: today's episode is a bit of an emotional rollercoaster — we've got a big security win, some honest lab feedback, and a very personal share about my dad's funeral. Buckle up....

17 Heinä 53min

7MS #730: Baby's First Project Swarm

7MS #730: Baby's First Project Swarm

Hey friends! Still your grieving pal over here, but also your swarming friend and Protecting My Network Edge host — because this week I've been tinkering with something called Project Swarm and I've g...

10 Heinä 25min

7MS #729: Pwning Dracarys

7MS #729: Pwning Dracarys

Hey friends! Still your grieving pal over here, but also your happy hacking host — because today we're diving into baby's first Dracarys! (Yes, I'm probably pronouncing that wrong. Yes, I'm going to k...

4 Heinä 18min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
otetaan-yhdet
rss-vaalirankkurit-podcast
rss-podme-livebox
rss-voi-venaja
rss-seksicast
rss-girls-finish-f1rst
tervo-halme
rss-asiastudio
rss-kaikki-uusiksi
rss-pinnalla
linda-maria
rss-raha-talous-ja-politiikka
rss-kovin-paikka
nakokulma-oikealta-jussi-halla-ahon-blogin-kommentaarit
rss-mina-ukkola