7MS #376: Tales of SQL Injection Pwnage

7MS #376: Tales of SQL Injection Pwnage

Today's episode is brought to you by ITProTV. It’s never too late to start a new career in IT or move up the ladder, and ITProTV has you covered - from CompTIA and Cisco to EC-Council and VMWare. Get over 65 hours of IT training for free by visiting https://itpro.tv/7minute.

We cover a lot of ground today on a variety of topics:

  • I have an Oculus Quest now and I love it. My handle is turdsquirt if you ever wanna shoot some zombies together.

  • I share a story that yes, does involve poop - but only the mention of it. It's nothing like the epic tale (tail?) of my parents' dog pooping in my son's dresser drawers.

  • I had a really fun pentest recently where I found some good old school SQL injection. I took to Slack to share and since then, several of you have reached out to ask how I found the vulnerability. Here are some steps/tips I talk about on today's episode that will help:

    • Watch Sunny's Burp courses on Pluralsight to enhance your Burp abilities
    • Install CO2 from the BApp store
    • When doing a Web app pentest, feed various fields SQL injection payloads, such as the ones in PayloadsAlltheThings
    • Grab a copy of sqlmap
    • Use sites like this one to help tune your sqlmap commands to find vulnerabilities. In the end, my command I used to dump contents of important tables was this:

(See today's show notes on the 7MS Web site for more information!)

Episoder(687)

7MS #158: Pentesting in a Vacuum

7MS #158: Pentesting in a Vacuum

Today's swell show notes are at: https://7ms.us/7ms-158-pentesting-in-a-vacuum/

22 Feb 201610min

7MS #157: Infosec News and Links Roundup

7MS #157: Infosec News and Links Roundup

Today's show notes are here: https://7ms.us/7ms-157-infosec-news-and-links-roundup/

19 Feb 201611min

7MS #156: OFF-TOPIC - 3 Ways to be a More Connected Parent

7MS #156: OFF-TOPIC - 3 Ways to be a More Connected Parent

Today's show notes: https://7ms.us/7ms-156-off-topic-3-ways-to-be-a-more-connected-parent/

17 Feb 201610min

7MS #155: Million Dollar Pentest Idea, Notepad Tricks and LL Bean Jackets for Dogs

7MS #155: Million Dollar Pentest Idea, Notepad Tricks and LL Bean Jackets for Dogs

Here are the show notes for today: https://7ms.us/7ms-155-million-dollar-pentest-idea-notepad-tricks-and-ll-bean-jackets-for-dogs/

16 Feb 20169min

7MS #154: Friday Infosec News and Links Roundup

7MS #154: Friday Infosec News and Links Roundup

Episode show notes are here: https://7ms.us/7ms-154-friday-infosec-news-and-links-roundup/.

12 Feb 201613min

7MS #153: OFF-TOPIC - Ex Machina (and special musical guest)

7MS #153: OFF-TOPIC - Ex Machina (and special musical guest)

Today's episode is a movie review of Ex Machina (how the FRICK do you pronounce that?) and closes out with special musical guest, Sweet Surrender!

10 Feb 201611min

7MS #152: Review of the Almond 2015 Wireless Router

7MS #152: Review of the Almond 2015 Wireless Router

This is a mini-review of the Almond 2015 router by Securifi. This is NOT a paid advertisement or endorsement. I just happen to REALLY like this little router.

8 Feb 201610min

7MS #151: Friday Infosec News and Links Roundup

7MS #151: Friday Infosec News and Links Roundup

Here are some of my favorite stories and links for this week! Training opportunities NMAP course from Udemy - $24 for a limited time (I think) How to handle the the thoughtless compliance zombie hordes - by BHIS is coming up Tuesday February 16th from 2-3 ET. The price is free! Pivot Project touts itself as "a portfolio of interesting, practical, enlightening, and often challenging hands-on exercises for people who are trying to improve their mastery of important cybersecurity skills. News It is absurdly easy for attackers to destroy your Web site in 10 minutes. Secure your home network better using advice from the SANS Ouch! newsletter. Chromodo (part of Comodo's Internet Security)disables same-origin policy which basically disables Web security. Wha?! Virus total now looks at firmware images as well. We can soon wave goodbye to Java in the browser forever!. Kinda. Tools Here's a nice SSL/TLS-checking checklist for pentesters. Kali is moving to a rolling release configuration pretty soon. Update yours before April 15!

5 Feb 201611min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
forklart
stopp-verden
popradet
fotballpodden-2
nokon-ma-ga
dine-penger-pengeradet
det-store-bildet
bt-dokumentar-2
unitedno
hva-star-du-for
aftenbla-bla
rss-penger-polser-og-politikk
rss-ness
e24-podden
rss-borsmorgen-okonominyhetene
rss-dannet-uten-piano
oppdatert