Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Pen Test War Stories - Why My Job Is So Easy and How You Can Make It Harder

via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore pen testing techniques and common security vulnerabilities in this 49-minute conference talk from GrrCON 2017. Dive into external network attacks, focusing on password spraying, active reconnaissance, and exploiting weak domain passwords. Learn about Metasploit's rogue SMB server, capturing NTLMV2 credentials, and the dangers of exposed administrator panels. Examine the risks associated with lack of multi-factor authentication, principle of least privilege, and legacy Windows broadcast protocols. Discover SMB relay attacks, insecure password storage in Group Policy Preferences, and pivoting through VPN split tunneling. Gain insights on remediation strategies for various vulnerabilities, including SMB signing, cached credentials, and shared virtual centers. Enhance your cybersecurity knowledge and learn how to make a pen tester's job more challenging.

Syllabus

Intro
External Network - Top Three
Password Spraying - Identify User Accounts
Active Reconnaissance
Password Spraying the Seasons Once you have your list of usernames begin password spraying.
Cheers to the Summer of 2017!
Weak Domain Passwords - Remediation
Metasploit Rogue SMB Server
Capture NTLMV2 Credentials
Good Users vs Bad Network Egress Rules
Lack of Multi-Factor Authentication (MFA)
Exposed Administrator Panels Used for website or application maintenance Enhanced feature set which is a highly valuable target
Lack of Principle of Least Privilege
Legacy Windows Broadcast Protocols
Hash Captured with Responder
SMB Relay Attack
MultiRelay.py Example
SMB Signing Disabled - Remediation
Cached Credentials - Remediation
Insecure Password Storage in GPP
Insecure GPP Password Storage - Remediation Apply B2962486 prevents password data from being stored in GPP
Pivoting through VPN Split Tunneling
VPN Split Tunneling - Remediation
Shared Virtual Center - Remediation
Conclusion

Reviews

Start your review of Pen Test War Stories - Why My Job Is So Easy and How You Can Make It Harder

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.