
7 Minute Security
743 episodes — Page 12 of 15

7MS #192: Podcast Like Nobody's Listening and Blog Like Nobody's Reading
Show notes here: https://7ms.us/7ms-192-podcast-like-nobodys-listening/

7MS #191: Vulnhub Walkthrough - Kevgir
Show notes: https://7ms.us/7ms-191-vulnhub-walkthrough-kevgir/

7MS #190: Infosec News and Links Roundup
Show notes: https://7ms.us/7ms-190-infosec-news-and-links-roundup/

7MS #189: OFFTOPIC - Reviews of The Family Fang and Tumbledown
Show notes: https://7ms.us/7ms-189-offtopic-reviews-of-the-family-fang-and-tumbledown/

7MS #188: Vulnhub Walkthrough - DroopyCTF
Show notes: https://7ms.us/7ms-188-vulnhub-walkthrough-droopyctf/

7MS #187: Infosec News and Links Roundup
Show notes: https://7ms.us/7ms-187-infosec-news-and-links-roundup/

7MS #186: OFFTOPIC - Reviews of Brooklyn and The Revenant
Show notes: https://7ms.us/7ms-186-offtopic-reviews-of-brooklyn-and-the-revenant/

7MS #185: Vulnhub Walkthrough - Lord of the Root
Show notes here: https://7ms.us/7ms-185-vulnhub-walkthrough-lord-of-the-root/

7MS #184: Infosec News and Links Roundup
Show notes here: https://7ms.us/7ms-184-infosec-news-and-links-roundup/

7MS #183: OFFTOPIC-The Invitation
Show notes here: https://7ms.us/7ms-183-offtopic-the-invitation/

7MS #182: Vulnhub Walkthrough - SickOs
Show notes here: https://7ms.us/7ms-182-vulnhub-walkthrough-sickos/

7MS #181: Infosec News and Links Roundup
Show notes here: https://7ms.us/7ms-181-infosec-news-and-links-roundup/

7MS #180: Vulnhub Walkthrough: Skydog CTF
Show notes here: https://7ms.us/7ms-180-vulnhub-walkthrough-skydog-ctf/

7MS #179: Bring New Life to an Old Mac with OSX Server
Show notes here: https://7ms.us/7ms-179-bring-new-life-to-an-old-mac-with-osx-server/

7MS #178: Infosec News and Links Roundup
Show notes here: https://7ms.us/7ms-178-infosec-news-and-links-roundup/

7MS #177: A Not Totally Sucky Way to Backup and Share Photos
Show notes are here: https://7ms.us/7ms-177-a-not-totally-sucky-way-to-backup-and-share-photos/

7MS #176: DIY SSH Honeypot with Cowrie
Check out the show notes here: https://7ms.us/7ms-176-diy-ssh-honeypot-with-cowrie-2/

7MS #175: Infosec News and Links Roundup
Show notes are here: https://7ms.us/7ms-175-infosec-news-and-links-roundup/

7MS #174: DIY SSH Honeypot with Kippo - Part 2
Show notes here: https://7ms.us/7ms-174-diy-ssh-honeypot-with-kippo-part-2/

7MS #173: DIY SSH Honeypot with Kippo
Show notes here: https://7ms.us/7ms-173-diy-ssh-honeypot-with-kippo/

7MS #172: Infosec News and Links Roundup
Show notes here: https://7ms.us/7ms-172-infosec-news-and-links-roundup/

7MS #171: OFF-TOPIC - Easter Music
Show notes (actually, MUSIC notes in this case) can be found here: https://7ms.us/7ms-161-off-topic-easter-music/

7MS #170: Pentesting in a Vacuum - Part 3
Show notes are here: https://7ms.us/7ms-170-pentesting-in-a-vacuum-part-3/

7MS #169: Infosec News and Links Roundup
Show notes are here: https://7ms.us/7ms-169-infosec-news-and-links-roundup/

7MS #168: Upgrading and Securing Your Digital Ocean Ghost Blog
Show notes are here! Go to https://7ms.us/7ms-168-upgrading-and-securing-your-digital-ocean-ghost-blog/

7MS #167: My Misadventures with SOAP Web Services
Show notes are here: https://7ms.us/7ms-167-my-first-dandy-experience-with-soap-web-services/

7MS #166: Infosec News and Links Roundup
Show notes are here: https://7ms.us/7ms-166-infosec-news-and-links-roundup/

7MS #165: DIY Podcast
Show notes for today's episode are right here: https://7ms.us/7ms-165-diy-podcast/

7MS #164: Pentesting in a Vacuum - Part 2
Check out the show notes for today's episode here: https://7ms.us/7ms-164-pentesting-in-a-vacuum-part-2/

7MS #163: Infosec News and Links Roundup
Show notes here: https://7ms.us/7ms-163-infosec-news-and-links-roundup/

7MS #162: OFF-TOPIC - Deadpool
Show notes for today's episode are here: https://7ms.us/7ms-162-off-topic-deadpool/

7MS #161: DIY Wifi Network Graphing & Dojo Scavenger Vulnerable Webapp
Show notes are here - enjoy! https://7ms.us/7ms-161-diy-wifi-network-graph-and-dojo-scavenger-vulnerable-webapp/

7MS #160: Infosec News and Links Roundup
Today's show notes are here: https://7ms.us/7ms-160-friday-infosec-news-and-links-roundup/

7MS #159: OFF-TOPIC - What Size Company is Right for Me? (and a review of the Steve Jobs movie)
Today's show notes are here: https://7ms.us/7ms-159-off-topic-what-size-company-is-right-for-me/

7MS #158: Pentesting in a Vacuum
Today's swell show notes are at: https://7ms.us/7ms-158-pentesting-in-a-vacuum/

7MS #157: Infosec News and Links Roundup
Today's show notes are here: https://7ms.us/7ms-157-infosec-news-and-links-roundup/

7MS #156: OFF-TOPIC - 3 Ways to be a More Connected Parent
Today's show notes: https://7ms.us/7ms-156-off-topic-3-ways-to-be-a-more-connected-parent/

7MS #155: Million Dollar Pentest Idea, Notepad Tricks and LL Bean Jackets for Dogs
Here are the show notes for today: https://7ms.us/7ms-155-million-dollar-pentest-idea-notepad-tricks-and-ll-bean-jackets-for-dogs/

7MS #154: Friday Infosec News and Links Roundup
Episode show notes are here: https://7ms.us/7ms-154-friday-infosec-news-and-links-roundup/.

7MS #153: OFF-TOPIC - Ex Machina (and special musical guest)
Today's episode is a movie review of Ex Machina (how the FRICK do you pronounce that?) and closes out with special musical guest, Sweet Surrender!

7MS #152: Review of the Almond 2015 Wireless Router
This is a mini-review of the Almond 2015 router by Securifi. This is NOT a paid advertisement or endorsement. I just happen to REALLY like this little router.

7MS #151: Friday Infosec News and Links Roundup
Here are some of my favorite stories and links for this week! Training opportunities NMAP course from Udemy - $24 for a limited time (I think) How to handle the the thoughtless compliance zombie hordes - by BHIS is coming up Tuesday February 16th from 2-3 ET. The price is free! Pivot Project touts itself as "a portfolio of interesting, practical, enlightening, and often challenging hands-on exercises for people who are trying to improve their mastery of important cybersecurity skills. News It is absurdly easy for attackers to destroy your Web site in 10 minutes. Secure your home network better using advice from the SANS Ouch! newsletter. Chromodo (part of Comodo's Internet Security)disables same-origin policy which basically disables Web security. Wha?! Virus total now looks at firmware images as well. We can soon wave goodbye to Java in the browser forever!. Kinda. Tools Here's a nice SSL/TLS-checking checklist for pentesters. Kali is moving to a rolling release configuration pretty soon. Update yours before April 15!

7MS #150: OFF-TOPIC-Bone Tomahawk / Goodnight Mommy / Comedy Loves Misery
Preview16 wordsIn today's off-topic episode I review the following movies: Bone Tomahawk Goodnight Mommy Misery Loves Comedy

7MS #149: Securing Your Life - Part 3
This episode continues the series on securing your life - making sure all the security stuff related to your life is in order. Today we're particularly focusing on preparing to travel. What if (God forbid) the plane goes down? Who has access to your money, passwords, etc.?

7MS #148: OFF-TOPIC - Apple Watch Review
Yep, there are tons of people/blogs/magazines/children/pets who have provided reviews of the Apple Watch. This is mine.

7MS #147: DIY Hosted Mutillidae
In this episode I talk about how to build a cheap hosted Mutillidae server to safely hack away on while keeping other Internet prowlers out. Here are the basic commands to run to lock down the Digital Ocean droplet's iptables firewall: *Flush existing rules* **sudo iptables -F** *Allow all concurrent connections* **sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT** *Allow specific IPs/hosts to access port 80* **sudo iptables -A INPUT -p tcp -s F.Q.D.N --dport 80 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT** *Allow specific IPs/hosts to access port 22* **sudo iptables -A INPUT -p tcp -s F.Q.D.N --dport 22 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT** *Block all other traffic:* **sudo iptables -P INPUT DROP** *Provide the VPS loopback access:* **sudo iptables -I INPUT 1 -i lo -j ACCEPT** *Install iptables-persistent to ensure rules survive a reboot:* **sudo apt-get install iptables-persistent** *Start iptables-persistent service* **sudo service iptables-persistent start** *If you make iptables changes after this and they don't seem to stick, do this:* **sudo iptables-save > /etc/iptables/rules.v4** See this Digital Ocean article for more information.

7MS #146: Friday Infosec News and Links Roundup
Here are some of my favorite stories and links for this week! If you missed last week's BURN IT ALL! Webcast, it's now online as a Youtube video. There is still time to register for the Real World Web Penetration Testing Webinar. It's(Thursday, January 28 @ 1 p.m. CST) and $25 (cheap!) Trustwave is in big trouble after failing to find hackers under their noses. Their noses mustreally hurt because Mandiant was quick to point out the work done by Trustwave was "woefully inadequate." I'm scared of IoT stuff. Why? Oh, I don't know, because what happens when your Nest fails and leaves your buttcheeks freezing cold?!?!? Or what if hackers steal your doorbell, and thus your wifi password and pwn your network? Thankfully, OWASP now now has a top 10 for IoT stuff too. A researcher found some clever ways to abuse Lastpass with an exploit called Lostpass. Lastpassresponded with a security change wherein a Lastpass authentication from a new device requires approval via email. A new Sysinternals tool helps figure out if you have shady, unsigned files in c:\windows\system32. Oh, and for sure upgrade all your iThings ASAP. Apple patched some ugly security holes.

7MS #145: OFF-TOPIC - Sicario and The Walk
In today's off-topic episode I review two movies: Sicario and The Walk.

7MS #144: Shoulder-Surfing with Seasoned Pentesters
I recently had the opportunity to shoulder-surf with some seasoned Webapp pentesters, and wanted to share what I learned about their tools, techniques and methodologies.

7MS #143: Friday Infosec News and Links Roundup
Here are some of my fav' stories and links for this week! * Burn it all...The New Security Fundamentals **(Wednesday, January 20 @ 1 p.m. CST)**: a free Webinar on setting up the "*core technical things you need to do for your security program*." I've attended many Webinars from the BHIS group and they're always informative and humorous. * Real World Web Penetration Testing **(Thursday, January 28 @ 1 p.m. CST)**: a $25 Webinar on going through "*a real world penetration test. We will explore the methodology and procedures Secure Ideas follows as we test web applications. The course will also walk through some tricks and tips on how to focus your testing on likely flaws*." I have seen four of their recorded courses before and found them to be *absolutely* worth the money I spent, so I'm confident this upcoming session will be no exception. * Fortinet SSH backdoor not much to say except if you use any of the affected products, update immediately as they contain an SSH backdoor: * FortiOS v4.3.17 or any later version of FortiOS v4.3 (available as of July 9, 2014) * FortiOS v5.0.8 or any later version of FortiOS v5.0 (available as of July 28, 2014) * Any version of FortiOS v5.2 or v5.4 * Hacker sentenced to 334 years in prison for operating a phishing Web site similar to that of a legit banking Web site. Moral of the story? Don't do that. * Don't use IE 8, 9 or 10 anymore! unless you like to live dangerously.