Black Hills Information Security
MailFail: Whos Spoofing your Email, and How are they Doing it? #livestream #infosec #email #server
updated
Learn more about Attack Emulation Tools here: antisyphontraining.com/attack-emulation-tools-atomic-red-team-caldera-and-more-w-carrie-roberts
I also have a "PowerShell For InfoSec: What You Need to Know!" course:
antisyphontraining.com/powershell-for-infosec-what-you-need-to-know
In this Black Hills Information Security (BHIS) webcast, we will introduce you to Portswigger's Burp - a powerful tool for web application security testing. We will cover the key capabilities of Burp and demonstrate how it can be used to identify vulnerabilities in web applications.
Whether you are a beginner or an experienced security professional, this webcast will provide valuable insights into this powerful Pentesting tool and how it can help you improve the security of your web applications.
Join Chris Traynor (@cstraynor ) as he discusses this essential tool for web application security testing.
Come hang out with us, it will be a gas!
Chat with your fellow attendees in the Black Hills Infosec Discord server here: discord.gg/BHIS -- in the #webcast-live-chat channel.
Please join us to learn all about SMUDGE!
00:00 - FEATURE PRESENTATION: The Top $_num Reasons You Got Hacked in 2022
00:57 - A little Intro
01:58 - Executive Problem Statement
04:18 - 2020’s Top Exploited CVEs
07:41 - 2021 Top Exploited CVEs
10:57 - The Transition Slide
13:14 - Hackers Though
16:04 - Investigation Methodology
18:57 - 10: Firewalls
26:17 - 9: Message Integrity
30:55 - 8: Defaults
37:35 - 7: Patching
39:39 - 6: Weak Protocol Abuse
43:50 - 5: Web Apps
46:08 - 4: Employees
48:47 - 3: Optics (Lack Thereof)
51:27 - 2: ADCS
53:50 - 1: Credentials
57:21 - Closing and Questions
Yes, the webcast title is clickbait. We know.
But...organizations keep getting hacked. Almost every day another organization gets criticized across our news feeds for losing more data, PII, and secrets. And we have an interesting perspective on the causes of and some possible solutions for organizations willing to listen.
After taking a look through our 2022 contracts and findings, we would like to offer you a perspective through the looking glass. In this Black Hills Information Security (BHIS) & Antisyphon webcast, we have our top findings (why you got popped) and our recommendations (years of our expertise) to share. Let our experiences guide your security programs in 2023.
Together, let's keep pushing the detection needle down from the industry approximation of 200 days to breach detection and 75 more to containment...
We are looking forward to spending some time with you!
Chat with your fellow attendees in the Infosec Knowledge Sharing Discord server here: discord.gg/fr5wqbF -- in the #webcast-live-chat channel
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
antisyphontraining.com/linux-command-line-dojo-w-hal-pomeranz
antisyphontraining.com/linux-forensics-w-hal-pomeranz
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
antisyphontraining.com/professionally-evil-cissp-mentorship-program
antisyphontraining.com/professionally-evil-api-testing
antisyphontraining.com/red-team-fundamentals-for-active-directory
antisyphontraining.com/owasp-top-10
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
07:02 - BHIS - Talkin’ Bout [infosec] News 2022-12-05
09:42 - Story # 1: There are no episodes of Darknet Diaries scheduled Q1
twitter.com/JackRhysider/status/1599115984262270977
11:38 - Story # 2: Elon Musk Meets With Apple CEO Tim Cook Amid Claims of Twitter App Store Dispute
macrumors.com/2022/11/30/elon-musk-tim-cook-meeting-apple-park
16:52 - Story # 3: Anker’s Eufy Cameras Caught Uploading Content to the Cloud Without User Consent
macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent
25:32 - Story # 3b: Eufy caught lying about local-only security cameras with footage sent to cloud, accessible in unencrypted streams
9to5google.com/2022/12/01/eufy-camera-cloud-security-leak
29:08 - Story # 4: FCC faces long road in stripping Chinese tech from US telecom networks
cyberscoop.com/fcc-huawei-zte-security-risks
36:33 - Story # 5: TikTok NSFW if you work for the South Dakota government
theregister.com/2022/11/30/tiktok_nsfw_if_you_work
39:54 - Story # 6: Never-before-seen malware is nuking data in Russia’s courts and mayors’ offices
arstechnica.com/information-technology/2022/12/never-before-seen-malware-is-nuking-data-in-russias-courts-and-mayors-offices
44:10 - Story # 7: Lessons from Russia’s cyber-war in Ukraine
economist.com/science-and-technology/2022/11/30/lessons-from-russias-cyber-war-in-ukraine
46:29 - Story # 8: DHS Cyber Safety Review Board to focus on Lapsus$ hackers
cyberscoop.com/cybersecurity-review-board-lapsus
52:03 - Story # 8b: Cyber Safety Review Board to Conduct Second Review on Lapsus$
dhs.gov/news/2022/12/02/cyber-safety-review-board-conduct-second-review-lapsus
52:56 - Story # 9: Rackspace rocked by ‘security incident’ that has taken out hosted Exchange services
theregister.com/2022/12/03/rackspace_security_incident_hosted_exchange
59:19 - Story # 10: Red Alert: The SFPD Want the Power to Kill with Robots
eff.org/deeplinks/2022/11/red-alert-sfpd-want-power-kill-robots
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
00:00 - FEATURE PRESENTATION
00:27 - WhoAMI
01:22 - Warnings
03:05 - Why a Home Lab?
05:14 - Goals of a Home Lab
05:57 - Homelab Parts
06:47 - Network
07:15 - Internet
07:55 - Firewall
09:04 - Firewall Options
13:32 - Firewall Diagram
14:27 - Switch
15:29 - Switch Options
15:56 - WiFI
17:18 - Wifi Hardware
17:41 - Storage
18:45 - Storage RAID
20:54 - Storage Types
21:29 - Storage Local Vs NAS
23:00 - Storage NAS Build
25:03 - Storage NAS Buy
26:26 - Compute
27:53 - Compute X86-64
28:40 - Compute AMD Desktop
29:45 - Compute AMD Laptop
30:52 - Compute ARM
32:40 - Compute RAM
33:51 - Compute PCI
34:50 - Compute GPU
36:07 - Compute Management
37:33 - Compute Laptop
38:15 - Compute Mini PC / Desktop
38:55 - Compute Server
39:35 - Compute Options
43:41 - Hardware Deals
44:17 - Virtualization / Containers
46:06 - Automation
47:07 - Applications
47:30 - AD Lab
48:02 - Detection Lab
48:25 - Self Hosted
49:29 - IDS / IPS
49:48 - Security Distro
50:27 - Logging
50:57 - HELK
51:24 - Cloud
51:58 - Cloud Providers
52:10 - Cloud Lab
53:49 - Cloud on the Cheap
54:17 - Community
54:37 - Recap
55:34 - Questions and Closing
In this Black Hills Information Security (BHIS) & Antisyphon webcast, we will learn all about home labs, what they are, recommendations on what to buy, and what you can do with them.
The world of home labs can be as simple as one computer and as complex as a cluster in a server rack. The wildest thing is what you can do with these home labs and how they can help you learn IT concepts firsthand.
On top of running stuff at home, we will discuss how to use the cloud to augment your home lab and when it makes the most sense.
We hope to see you all there!
Chat with your fellow attendees in the Infosec Knowledge Sharing Discord server here: discord.gg/fr5wqbF -- in the #webcast-live-chat channel.
///Slides for this webcast:
blackhillsinfosec.com/wp-content/uploads/2022/12/SLIDES_How-to-Homelab.pdf
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
antisyphontraining.com
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
antisyphontraining.com/security-defense-and-detection-ttx-w-amanda-berlin-and-jeremy-mio
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
In this video we take intel from the Mitre ATT&CK framework and makes it actionable using the Atomic Red Team library of scripted cyber-attacks. This spotlight highlights a defense evasion technique using PowerShell to execute Base64 encoded commands, both from the command line and stored persistently in the Windows registry. Learn more about Attack Emulation Tools here: antisyphontraining.com/attack-emulation-tools-atomic-red-team-caldera-and-more-w-carrie-roberts
01:49 - BHIS - Talkin’ Bout [infosec] News 2022-11-28
04:11 - Story # 1: Musk recruits engineers for “Twitter 2.0”
arstechnica.com/tech-policy/2022/11/musk-recruits-engineers-for-twitter-2-0-after-mass-layoffs-and-resignations
08:12 - Story # 2: Security experts are laying Mastodon’s flaws bare
techradar.com/news/security-experts-are-laying-mastodons-flaws-bare
16:49 - Story # 3: 5.4 million Twitter users’ stolen data leaked online — more shared privately
bleepingcomputer.com/news/security/54-million-twitter-users-stolen-data-leaked-online-more-shared-privately
20:15 - Story # 4: 34 Russian Cybercrime Groups Stole Over 50 Million Passwords with Stealer Malware
thehackernews.com/2022/11/34-russian-hacker-groups-stole-over-50.html
21:48 - Story # 5: Sonder confirms data breach, documents and other PII potentially compromised
infosecurity-magazine.com/news/sonder-confirms-data-breach
30:19 - Story # 6: Why Medibank should have paid the hackers
https://www.smh.com.au/business/consumer-affairs/this-is-a-business-for-them-why-medibank-should-have-paid-the-hackers-20221121-p5bzzn.html
33:17 - Story # 7: Hackers are locking out Mars Stealer operators from their own servers
techcrunch.com/2022/11/22/mars-stealers-flaw-lock-out
36:17 - Story # 8: Ransomware gang says it won’t attack AirAsia again due to the “chaotic organisation” and sloppy security of hacked airline’s network
grahamcluley.com/ouch-ransomware-gang-says-it-wont-attack-airasia-again-due-to-the-chaotic-organisation-and-sloppy-security-of-hacked-companys-network
42:48 - Story # 9: Over 1,600 Docker Hub Repositories Were Found to Hide Malware
heimdalsecurity.com/blog/over-1600-docker-hub-repositories-were-found-to-hide-malware
49:14 - Story # 10: New Windows Server updates cause domain controller freezes, restarts
bleepingcomputer.com/news/microsoft/new-windows-server-updates-cause-domain-controller-freezes-restarts
56:33 - Story # 11: Making Cobalt Strike harder for threat actors to abuse
cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
10:45 - BHIS - Talkin’ Bout [infosec] News 2022-11-21
12:11 - Story # 1: Elon Musk gives employees two days to commit to ‘hardcore’ Twitter or lose their jobs
engadget.com/best-black-friday-tv-deals-2022-144506723.html
16:28 - Story # 1b: Twitter Two-Factor Authentication Has a Vulnerability - UPDATED
bankinfosecurity.com/twitter-second-factor-authentication-has-vulnerability-a-20475
18:17 - Special Twitter Guest
21:05 - Story # 2: Stealing passwords from infosec Mastodon - without bypassing CSP
portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
24:04 - Story # 3: New Ransomware Data Is In: What’s Happening and How to Fight Back
darkreading.com/vulnerabilities-threats/new-ransomware-data-is-in-what-s-happening-and-how-to-fight-back
28:00 - Story # 4: Hive Ransomware Attackers Extorted $100 Million from Over 1,300 Companies Worldwide
thehackernews.com/2022/11/hive-ransomware-attackers-extorted-100.html
36:58 - Story # 5: New ransomware encrypts files, then steals your Discord account
bleepingcomputer.com/news/security/new-ransomware-encrypts-files-then-steals-your-discord-account
41:11 - Story # 6: Black Friday and Cyber Monday, crooks are already at work
securityaffairs.co/wordpress/138737/cyber-crime/black-friday-and-cyber-monday-scams.html
46:14 - Story # 7: 1Password embraces a passwordless future
theverge.com/2022/11/17/23464817/1password-passkey-support-security-apple-google
49:10 - Story # 2b reprise
51:53 - Story # 8: Euro Authorities Warn World Cup Fans Over Qatari Apps
infosecurity-magazine.com/news/euro-authorities-world-cup-fans
55:52 - Story # 9: TSA Found a Double-Edged Knife Hidden in a Gaming Laptop
tomshardware.com/news/airport-tsa-knife-hidden-gaming-laptop
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
00:00 - Intro/Pre-Show Banter
03:01 - Overview of Ansible
06:30 - Why Ansible
09:39 - Pitfalls
12:05 - Demo - installation
15:52 - Ansible Playbook
20:15 - Running playbook
24:11 - Installing Docker w/ Ansible
34:22 - Q&A
Description: Ralp May joins us on AASLR to give us a beginner friendly demo of Ansible an open-source configuration management tool that aids in configuring Host Operating system.
Antisyphon Socials
Twitter: twitter.com/Antisy_Training
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Shirts
spearphish-general-store.myshopify.com/collections/antisyphon-training
Educational Infosec Content
Black Hills Infosec YouTube: youtube.com/blackhillsinformationsecurity
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
antisyphontraining.com/enterprise-attacker-emulation-and-c2-implant-development-w-joff-thyer
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
02:39 - Story # 1: Hackers Dump Australian Health Records Online After Insurer Refuses to Pay Ransom
gizmodo.com/hackers-health-info-online-medibank-pay-onion-dark-web-1849760742
10:33 - Story # 2: TransUnion LLC Confirms Recent Data Breach with State Attorney General’s Office
jdsupra.com/legalnews/transunion-llc-confirms-recent-data-6828319
18:50 - Story # 3: Russian LockBit ransomware operator arrested in Canada
bleepingcomputer.com/news/security/russian-lockbit-ransomware-operator-arrested-in-canada
23:43 - Story # 4: The downfall of FTX’s Sam Bankman-Fried sends shockwaves through the crypto world
npr.org/2022/11/14/1136482889/ftx-sam-bankman-fried-shockwaves-crypto
41:18 - Story # 5: Install Latest Windows Update ASAP! Patches Issued for 6 Actively Exploited Zero-Days
thehackernews.com/2022/11/install-latest-windows-update-asap.html
43:10 - Story # 6: Elon Musk is putting Twitter at risk of billions in fines, warns company lawyer
theverge.com/2022/11/10/23451198/twitter-ftc-elon-musk-lawyer-changes-fine-warning
52:13 - Story # 7: https://infosec.exchange/explore
56:12 - Story # 8: Microsoft Windows Sysmon Elevation of Privilege Vulnerability
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41120
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
00:00 - FEATURE PRESENTATION
01:48 - Roadmap
04:45 - AWS- Authentication
06:37 - Management Console
07:10 - Initial Access
08:20 - Public Accessibility of Resources
09:57 - Secrets in Code Repositories
11:24 - Phishing
12:30 - Resource Exploitation
14:00 - Post-Compromise Recon
15:27 - AWS Permissions
17:46 - Identity Vs Resource-based Policies
19:42 - AWS Command Line
24:04 - IAM Policy Enumeration
24:35 - Identifying Public Resources
28:38 - Privilege Escalation
29:14 - Instance Metadata Service
33:34 - User Data & ENV Vars
34:34 - Assume Role Policies
37:04 - Leveraging Scanning Tools
38:00 - Pacu
38:24 - ScoutSuite
39:09 - WeirdAAL
40:01 - DEMO!
54:34 - Resources
55:00 - Key Takeaways
56:04 - The End
Description: One of the most interesting things about cloud environments is that they tend to have an underlying API that can be leveraged for management of resources. But this API can also be abused by attackers for malicious purposes.
In this Black Hills Information Security (BHIS) webcast, senior security analyst Beau Bullock shows how attackers targeting cloud-based services like Amazon Web Services (AWS) can leverage API access to laterally move from resource to resource. Examples of post-compromise reconnaissance and privilege escalation will be detailed. A multi-resource pivot will be demonstrated to show how cloud-based lateral movement can look.
Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
05:27 - BHIS - Talkin’ Bout [infosec] News 2022-11-07
08:57 - Story # 1: Musk to cut half of Twitter jobs and end remote work for the rest, report says
24:22 - Story # 2: Dropbox Data Breach Another Multifactor Fail
25:10 - Story # 2b: Dropbox Breach: Hackers Unauthorizedly Accessed 130 GitHub Source Code Repositories
30:03 - Story # 3: Hundreds of U.S. news sites push malware in supply-chain attack
34:27 - Story # 4: New TikTok Privacy Policy Confirms Chinese Staff Can Access European Users’ Data
38:24 - Story # 5: A cyberattack blocked the trains in DenmarkSecurity Affairs
47:01 - Story # 6: Facebook probably has your phone number, even if you never shared it. Now it has a secret tool to let you delete it.
51:31 - Story # 7: China is likely stockpiling and deploying vulnerabilities, says Microsoft
55:00 - Story # 8: Hackers selling access to 576 corporate networks for $4 million
* Utilities such as dmidecode, fwupd, dbxtool, and Chipsec to explore devices and firmware
* Enumerating and updating firmware within your system using LVFS (Linux Vendor Firmware Service)
* Enabling Secure Boot and its components (and keeping your DBX up-to-date using new functionality in LVFS!)
* Discovering Intel ME/AMT and associated vulnerabilities
* Using Chipsec to understand the permissions applied (or not applied) on your SPI flash chip
Paul Asadoorian (Podcast Personality at Security Weekly) works for Eclypsium as the Firmware Security Evangelist.
Join the Infosec Knowledge Sharing Discord server: discord.gg/fr5wqbF
01:11 - BHIS - Talkin’ Bout [infosec] News 2022-10-31
04:17 - Story # 1: OpenSSL warns of critical security vulnerability with upcoming patch
- zdnet.com/article/openssl-warns-of-critical-security-vulnerability-with-upcoming-patch
05:00 - Story # 1b: Notes on OpenSSL remote memory corruption
- guidovranken.com/2022/06/27/notes-on-openssl-remote-memory-corruption
12:50 - Story # 2: GitHub Bug Exposed Repositories to Hijacking
- infosecurity-magazine.com/news/github-bug-hackers-hijack
16:47 - Story # 3: Gartner Identifies the Top 10 Strategic Technology Trends for 2023
- gartner.com/en/newsroom/press-releases/2022-10-17-gartner-identifies-the-top-10-strategic-technology-trends-for-2023
26:39 - Story # 4: Former U.K. Prime Minister Liz Truss’ Phone Allegedly Hacked By Kremlin Spies: Report
- forbes.com/sites/daveywinder/2022/10/30/former-uk-prime-minister-liz-trusss-phone-allegedly-hacked-by-kremlin-spies-report
35:41 - Story # 5: New Azov data wiper tries to frame researchers and BleepingComputer
- bleepingcomputer.com/news/security/new-azov-data-wiper-tries-to-frame-researchers-and-bleepingcomputer
In this Black Hills Information Security (BHIS) webcast, join Chris Traynor (@cstraynor) as he shares the tactics, techniques, and procedures (TTPs) for a Pentester.
Chat with your fellow attendees in the Infosec Knowledge Sharing Discord server here: discord.gg/fr5wqbF -- in the #webcast-live-chat channel.
/// Chapters
00:00 - Pentester Tactics, Techniques, and Procedures (TTPs) with Chris Traynor
00:21 - Whoami
00:56 - Agenda
02:36 - Baseline Terminology
08:12 - Reconnaissance — Tactic/Intended Effect
09:15 - Nmap — Tool/Mechanism
11:14 - Nmap — Execution
14:36 - Recon-ng – Tool/Mechanism
19:57 - Recon-ng — Execution
22:34 - Recon-ng — Cheatsheet
25:13 - Account Enumeration — Tactic/Intended Effect
26:10 - Burp Repeater — Tool/Mechanism
27:01 - Burp Repeater — Execution
33:51 - Password Spraying — Tactic/Intended Effect
39:15 - Burp Intruder — Tool/Mechanism
40:15 - Burp Intruder — Execution
44:17 - smb_login Module — Tool/Mechanism
45:51 - smb_login Module — Execution
47:56 - psexec Module — Execution
52:30 - Chris’s Other Talks
54:18 - Post Show Questions
Get-ADObject -SearchBase $((Get-ADRootDSE).schemaNamingContext) -LDAPFilter "(&(objectClass=attributeSchema)(searchFlags:1.2.840.113556.1.4.803:=128))" -properties * | select lDAPDisplayName,SearchFlags | ft -AutoSize
Get-ADObject -SearchBase $((Get-ADRootDSE).schemaNamingContext) -LDAPFilter "(&(objectClass=attributeSchema)(searchFlags:1.2.840.113556.1.4.803:=640))" -properties * | select lDAPDisplayName,SearchFlags | ft -AutoSize
github.com/neKuehn/MADs/blob/main/Invoke-ReplicateDirectoryChanges.ps1
///Securing AD
docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/best-practices-for-securing-active-directory
07:03 - BHIS - Talkin’ Bout [infosec] News 2022-10-24
08:40 - Story # 1: Australia’s No. 1 health insurer says hacker stole patient details
15:16 - Story # 2: Police tricked a ransomware gang into handing over its decryption keys. Here’s how they did it
23:01 - Story # 3: Experts Warn of Stealthy PowerShell Backdoor Disguising as Windows Update
27:39 - Story # 4: British company Interserve fined £4.4 million over ransomware attack
31:17 - Story # 5: Microsoft data breach exposes customers’ contact info, emails
36:50 - Story # 6: Microsoft fixes Windows TLS handshake failures in out-of-band updates
39:23 - Story # 7: A bug in Abode’s home security system could let hackers remotely switch off cameras
41:50 - Story # 8: Microsoft is bringing Android 13 to Windows 11 via WSA
48:18 - Story # 9: Airborne Drones Are Dropping Cyber-Spy Exploits in the Wild
52:17 - Story # 10: Zeek is Now a Component of Microsoft Windows
56:32 - Story # 11: Eight RTX 4090s Can Break Passwords in Under an Hour
00:03:31 - BHIS - Talkin’ Bout [infosec] News 2022-10-07
00:07:59 - Story # 1: The Verge: Cybersecurity Week 2022
- theverge.com/23365380/cybersecurity-week-series-phishing-encryption-device-security
00:10:07 - Story # 2: Google Cybersecurity Action Team Threat Horizons Report #4 Is Out!
- medium.com/anton-on-security/google-cybersecurity-action-team-threat-horizons-report-4-is-out-c221342004c3
00:27:02 - Story # 3: Caffeine service lets anyone launch Microsoft 365 phishing attacks
- bleepingcomputer.com/news/security/caffeine-service-lets-anyone-launch-microsoft-365-phishing-attacks
00:31:39 - Story # 4: AirTags in Checked Baggage
- daringfireball.net/linked/2022/10/10/airtags-checked-baggage
00:35:38 - Story # 5: International crackdown on West-African financial crime rings
- https://www.interpol.int/en/News-and-Events/News/2022/International-crackdown-on-West-African-financial-crime-rings
00:40:40 - Story # 6: Indian Energy Company Tata Power’s IT Infrastructure Hit By Cyber Attack
- thehackernews.com/2022/10/indian-energy-company-tata-powers-it.html
00:42:11 - Story # 6b: This Is How They Tell Me the World Ends: The Cyberweapons Arms Race
- amazon.com/This-They-Tell-World-Ends/dp/1635576059
01:00:16 - Story # 6c: Brave New War: The Next Stage of Terrorism and the End of Globalization
- amazon.com/Brave-New-War-Terrorism-Globalization/dp/0471780790
02:26 - BHIS - Talkin’ Bout [infosec] News 2022-10-10
04:35 - Story # 1: US airports’ sites taken down in DDoS attacks by pro-Russian hackers
- bleepingcomputer.com/news/security/us-airports-sites-taken-down-in-ddos-attacks-by-pro-
20:25 - Story # 2: Former Uber Security Chief Found Guilty of Hiding Hack From Authorities
- nytimes.com/2022/10/05/technology/uber-security-chief-joe-sullivan-verdict.html
32:25 - Story # 3: Fortinet says critical auth bypass bug is exploited in attacks
- bleepingcomputer.com/news/security/fortinet-says-critical-auth-bypass-bug-is-exploited-in-attacks
41:26 - Story # 4: A cracked copy of Brute Ratel post-exploitation tool leaked on hacking forums
- cybersecurityworldconference.com/2022/09/29/a-cracked-copy-of-brute-ratel-post-exploitation-tool-leaked-on-hacking-forums
00:00 - PreShow Banter™ — Dumpster Fire Friends
08:57 - Story # 1: High-severity Microsoft Exchange 0-day under attack threatens 220,000 servers
- arstechnica.com/information-technology/2022/09/high-severity-microsoft-exchange-0-day-under-attack-threatens-220000-servers
21:01 - Story # 2: Stealthy hackers target military and weapons contractors in recent attack
- bleepingcomputer.com/news/security/stealthy-hackers-target-military-and-weapons-contractors-in-recent-attack
27:24 - Story # 3: Putin grants Russian citizenship to Edward Snowden
- npr.org/2022/09/26/1125109303/putin-edward-snowden-russian-citizenship
30:46 - Story # 4: What the Securing Open Source Software Act does and what it misses
- zdnet.com/article/whats-what-in-the-united-states-securing-open-source-software-act
40:00 - Story # 4b: SecBSD Team
42:28 - Story # 5: New Malware Campaign Targeting Job Seekers with Cobalt Strike Beacons
- thehackernews.com/2022/09/new-malware-campaign-targeting-job.html
00:00 - PreShow Banter™
03:45 - BHIS - Talkin’ Bout [infosec] News 2022-09-26
06:15 - American Airlines Breach Exposes Customer and Staff Information infosecurity-magazine.com/news/american-airlines-breach-customer/k
22:56 - London police arrest, charge teen hacking suspect but won’t confirm GTA 6, Uber links theverge.com/2022/9/23/23368340/hacking-suspect-arrested-city-of-london-lapsus-gta-6-uber
29:35 - LockBit ransomware builder leaked online by “angry developer” bleepingcomputer.com/news/security/lockbit-ransomware-builder-leaked-online-by-angry-developer-
34:24 - Malwarebytes blocks Google, YouTube as malware theregister.com/2022/09/21/malwarebytes_blocks_google_domains
36:28 - AdGuard’s new ad blocker struggles with Google’s Manifest v3 rules bleepingcomputer.com/news/security/adguard-s-new-ad-blocker-struggles-with-google-s-manifest-v3-rules
41:48 - Adware on Google Play and Apple Store installed 13 million times bleepingcomputer.com/news/security/adware-on-google-play-and-apple-store-installed-13-million-times
45:39 - Revealed: US Military Bought Mass Monitoring Tool That Includes Internet Browsing, Email Data vice.com/en/article/y3pnkw/us-military-bought-mass-monitoring-augury-team-cymru-browsing-email-data
55:20 - SIM Swapper Abducted, Beaten, Held for $200k Ransom krebsonsecurity.com/2022/09/sim-swapper-abducted-beaten-held-for-200k-ransom
Description: Our September 26, 2022, edition of Talkin’ Bout[infosec]! Brought to you by Black Hills Information Security! We talk about infosec news every Monday at 4:30EST
Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
#bhis #infosec
Training: antisyphontraining.com/attack-emulation-tools-atomic-red-team-caldera-and-more-w-carrie-roberts
00:00 - Intro/Pre-Show Banter
00:55 - T1218 on MITRE ATT&CK
06:00 - Running Atomic Test #2
11:22 - Running command with ordinal #
16:40 - Atomic Test #4 Rundll32 advpack
21:23 - Testing INF and SCT file
31:37 - Atomic Test #13 Rundll32 with desk.cpl
33:53 - Review
35:46 - Defensive Thoughts
Description: Carrie Roberts join us to talk about Atomic red team, defense evasion and proxy execution through rundll32.
Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.co
#bhis #infosec
00:00 - PreShow Banter™ — Classic Game Consoles and How To Hack Them
06:09 - BHIS - Talkin’ Bout [infosec] News 2022-09-19
08:30 - Uber Security Update uber.com/newsroom/security-update
10:16 - A teen hacked Uber and announced it in the company Slack. Employees thought it was a joke mashable.com/article/uber-teen-hacker-slack-joke
36:10 - White House Releases First-Ever Comprehensive Framework for Responsible Development of Digital Assets whitehouse.gov/briefing-room/statements-releases/2022/09/16/fact-sheet-white-house-releases-first-ever-comprehensive-framework-for-responsible-development-of-digital-assets
41:53 - GTA 6 source code and videos leaked after Rockstar Games hack bleepingcomputer.com/news/security/gta-6-source-code-and-videos-leaked-after-rockstar-games-hack
51:13 - Microsoft Teams stores auth tokens as cleartext in Windows, Linux, Macs bleepingcomputer.com/news/security/microsoft-teams-stores-auth-tokens-as-cleartext-in-windows-linux-macs
54:28 - LockBit 3.0 Ransomware Victim: First bounty payout redpacketsecurity.com/lockbit-3-0-ransomware-victim-first-bounty-payout-50000
Description: Our September 19, 2022, edition of Talkin’ Bout[infosec]! Brought to you by Black Hills Information Security! We talk about infosec news every Monday at 4:30EST
Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Active Countermeasures YouTube: youtube.com/activecountermeasures
Antisyphon Training YouTube: youtube.com/antisyphontraining
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
#bhis #infosec
///Chapters
00:00:00 - FEATURE PRESENTATION: Coercions and Relays – The First Cred is the Deepest
00:00:20 - Agenda
00:00:45 - Why This Talk?
00:02:10 - Why This Works
00:03:44 - Option 1
00:04:53 - Option 2
00:09:02 - Recon Tools
00:09:16 - 01 - Basic Responder
00:11:16 - 02 - Simple Relay (Local Admin SMB to SMB)
00:14:41 - 03 - Dump AD Information HTTP to LDAP (IPv6 Poisoning)
00:16:39 - 04 – Fake Machine Account Creation via DHCP Poisoning (HTTP to LDAP)
00:18:43 - 05 - SMB to SOCKS AD Users, Groups and Machine Accounts Dump (SOCKS)
00:22:04 - 06 - Domain Administrator Privilege Escalation NetNTLM v1
00:26:57 - 07 - Machine Account Admin to (Exchange Trusted Subsystem Group)
00:29:41 - 08 - Printer LDAP Pass Back Attack
00:31:56 - 09 - MSSQL Relay via XP_DIRTREE
00:37:30 - 10 - SCCM Client Push Installation
00:39:07 - 11 - Files That Coerce (SMB Share)
00:42:33 - Take a break; Let’s all go to the lobby, have a snack!
00:43:01 - What is WebDAV?
00:45:37 - 12 - Remote Code Execution (RCE) via WebDAV to RBCD Using Unauthenticated PetitPotam Proxy
00:53:55 - 13 - Local Privilege Escalation (LPE) via WebDAV to RBCD (Change Lock Screen)
00:59:09 - 14 - Local Privilege Escalation (LPE) via WebDAV to Shadow Credentials (Remote C2)
01:07:22 - 15 - Unauthenticated ADCS User Templates Dump Via Web (SMB to HTTP)
01:09:57 - 16 - Active Directory Certificate Services (ADCS) ESC8 via C2 (PortBender)
01:13:50 - 17 - RemotePotato Privilege Escalation via RPC Protocol
01:16:53 - 18 - Kerberos Relay DNS Authentication via Mitm6 (Krbrelayx)
01:19:57 - 19 - Kerberos KrbRelay and KrbRelayUp Tools Local Privilege Escalation (LPE)
01:22:36 - Mitigation
01:24:50 - Credit & Reference
01:25:32 - Post Show Questions
In this 1.5-HOUR, Black Hills Information Security (BHIS) webcast, Gabriel Prud'homme will cover network protocol poisoning, relays, and abuses. Learn how to use Responder, Ntlmrelayx, and Mitm6. From PetitPotam to WebDAV remote and local privilege escalation, and much more.
Chat with your fellow attendees in the Infosec Knowledge Sharing Discord server here: discord.gg/fr5wqbF -- in the #webcast-live-chat channel.


