PLAY PODCASTS
7MS #634: Tales of Pentest Pwnage - Part 60

7MS #634: Tales of Pentest Pwnage - Part 60

7 Minute Security · Brian Johnson

July 26, 202432m 38s

Audio is streamed directly from the publisher (traffic.libsyn.com) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

Hi, today's tale of pentest pwnage covers a few wins and one loss:

  1. A cool opportunity to drop Farmer "crops" to a domain admin's desktop folder via PowerShell remote session
  2. Finding super sensitive data by dumpster-diving into a stale C:\Users\Domain-Admin profile
  3. Finding a vCenter database backup and being unable to pwn it using vcenter_saml_login