
Audio is streamed directly from the publisher (traffic.libsyn.com) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.
Show Notes
Hi, today's tale of pentest pwnage covers a few wins and one loss:
- A cool opportunity to drop Farmer "crops" to a domain admin's desktop folder via PowerShell remote session
- Finding super sensitive data by dumpster-diving into a stale C:\Users\Domain-Admin profile
- Finding a vCenter database backup and being unable to pwn it using vcenter_saml_login