Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
headphones
7 Minute Security

7 Minute Security

Brian Johnson

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.
bookmark
Share icon

All episodes

Best episodes

Top 10 7 Minute Security Episodes

Goodpods has curated a list of the 10 best 7 Minute Security episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to 7 Minute Security for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite 7 Minute Security episode by adding your comments to the episode page.

7 Minute Security - 7MS #116: Tips for a Succesful Vulnerability Scan
play

12/08/15 • 14 min

In this episode I complain about getting stuck in NY for two days, and also how to efficiently scan for vulnerabilities when your time is crunched.

bookmark
plus icon
share episode
  • How much fun I had attending and speaking at Netwrix Connect
  • Being a sales guy in conference situations without being an annoying sales guy in conference situations
  • A recap of the talk I co-presented about high profile breaches and lessons we can learn from them
bookmark
plus icon
share episode
7 Minute Security - 7MS #641: DIY Pentest Dropbox Tips – Part 10
play

09/13/24 • 27 min

Today we’re revisiting the fun world of automating pentest dropboxes using Proxmox, Ansible, Cursor and Level. Plus, a tease about how all this talk about automation is getting us excited for a long-term project: creating a free/community edition of Light Pentest LITE training!

bookmark
plus icon
share episode
7 Minute Security - 7MS #617: Tales of Pentest Pwnage – Part 55
play

03/29/24 • 36 min

Hey friends, today we’ve got a tale of pentest pwnage that covers:

  • Passwords – make sure to look for patterns such as keyboard walks, as well as people who are picking passwords where the month the password changed is part of the password (say that five times fast)!
  • Making sure you go after cached credentials
  • Attacking SCCM – Misconfiguration Manager is an absolute gem to read, and The First Cred is the Deepest – Part 2 with Gabriel Prud’homme is an absolute gem to see. Also, check out sccmhunter for all your SCCM pwnage needs.
bookmark
plus icon
share episode
7 Minute Security - 7MS #18: Wireless Security 101 (audio)
play

06/22/14 • 7 min

In this episode I talk about some wireless security basics that we’re not seeing when out on assessments. Download: 7MS #18: Wireless Security 101 (audio) Show notes: WEP encryption is very, very bad. It’s easy to crack. Don’t use it. Wifite will demonstrate how easy it is to crack WEP. Stronger encryption such as WPA/WPA2...

bookmark
plus icon
share episode

SafePass.me is the only enterprise solution to protect organizations against credential stuffing and password spraying attacks. Visit safepass.me for more details, and tell them 7 Minute Security sent you to get a 10% discount!

I'm sorry it took me forever and a day to get this episode up, but I'm thrilled to share part 4 (the final chapter - for now anyways) of my interview with the red team guys, Ryan and Dave!

In today's episode we talk about:

  • Running into angry system admins (that are either too fired up or not fired up enough)
  • Being wrong without being ashamed
  • When is it necessary to make too much noice to get caught during an engagement?
  • What are the top 5 tools you run on every engagement?
  • How do you deal with monthly test reports indefinitely being a copy/paste of the previous month's report?
  • How do you deal with clients who scope things in such as way that the test is almost impossible to conduct?
  • How do you deal with colleagues who take findings as their own when they talk with management?
  • How do you work with clients who don't know why they want a test - except to check some sort of compliance checkmark?
  • What is a typical average time to complete a pentest on a vendor (as part of a third-party vendor assessment)?
  • How could a fresh grad get into a red team job?
  • What do recruiters look for candidates seeking red team positions?
  • If a red team is able to dump a whole database of hashes or bundle of local machine hashes, should they crack them?
  • What do you do when you're contracted for a pentest, but on day one your realize the org is not at all ready for one?
  • What's your favorite red team horror story?
bookmark
plus icon
share episode
7 Minute Security - 7MS #279: Patching Solutions Bake-Off - Part 4
play

09/28/17 • 15 min

Intro

The patching solutions review concludes this week with Ivanti's patch solution, as well as PDQ Deploy/Inventory.

As a quick reminder, here's where our bake-off currently sits:

Quick reminder: none of these solutions are bribing me with fat wads of cash to plug their products. Some day I hope to have such problems, but today is not that day.

Ivanti

You might know Ivanti as Shavlik - that's the product name I'm more familiar with anyways. Back in February, Shavlik became Ivanti.

Pros
  • Pretty easy to install and manage - even without a deep background in IT (in today's episode I tell a story that can back this claim based on my experience)
  • Does a solid job of applying patching Windows OS and third party
Cons
  • Pricing is a little steep - last figures I saw were ~$80 per server, per year and ~$40 per workstation, per year.
  • ITScripts library (that allows for GPO-style policy enforcement) is a little slim when compared to similar functionality offered from other solutions
PDQ Deploy/Inventory Pros
  • Lets you crazy with building custom packages you can deploy to granular groups
  • Awesome online help resources, including a YouTube video library that's got a video for just about everything
  • Quick response to support tickets
Cons
  • A bit more complicated to get comfortable with than the other solutions
  • A little confusing on the Windows patching side - not quite as "point and patch" as some of the other solutions
  • Agentless system - machines have to be able to "see" the PDQ
bookmark
plus icon
share episode
7 Minute Security - 7MS #248: How to Hack the 10 O'clock News
play

03/09/17 • 11 min

Show notes are here.

bookmark
plus icon
share episode
7 Minute Security - 7MS #193: News and Links Roundup
play

05/20/16 • 14 min

bookmark
plus icon
share episode
7 Minute Security - 7MS #357: 7 Minutes of IT and Security Tips
play

04/11/19 • 7 min

Today I'm launching an ongoing series called 7MOIST. It stands for:

  • 7
  • Minutes
  • of
  • IT
  • and
  • Security
  • Tips

The wildest, craziest, nuttiest part of this series is that each episode will be 7 minutes long!

I know, I know! You're saying, "Wait a sec, bub, isn't that why this podcast is called 7 Minute Security in the first place?" And yes, you'd be right.

Basically, this is my way of going old school and getting back my podcast "roots" by delivering an episode before we had an intro jingle, interviews, sponsors, banter about hot cocoas or an outro song. Nothing but delicious content today friends, Enjoy!

Today's theme is:

Windows command line shortcuts and tips: Creative ways to play with cmd

Basically, you can do Windows Key + R then type cmd and Enter for quick access to command line.

But lets do some more fun stuff. Wanna open a command window from the desktop and launch a command in one swoop? Try this:

cmd /k

For example:

cmd /k ping 192.168.0.1

The cmd /k part opens a command window, and then ping 192.168.0.1 can be whatever command you also want to run on the fly.

And if you want to start programs and/or open files right from the command line, you can do that (in most cases) by just typing the program name, like:

notepad

Or, get really fancy and add a document name after the command. For example:

notepad meow.txt

If meow.txt doesn't exist, Notepad will simply ask you to create it!

Finding files faster

Call me crazy, but the Windows find/search feature sometimes doesn't find stuff that I know is there. So I still like using old school DOS commands for this. I might do something like:

cd \ dir /s *brian*.doc

The dir stands for directory, and the /s tells the system to search recursively.

See 7ms.us for the rest of today's show notes!

bookmark
plus icon
share episode

Show more best episodes

Toggle view more icon

FAQ

How many episodes does 7 Minute Security have?

7 Minute Security currently has 649 episodes available.

What topics does 7 Minute Security cover?

The podcast is about News, Tech News, Podcasts and Technology.

What is the most popular episode on 7 Minute Security?

The episode title '7MS #420: Tales of Internal Pentest Pwnage - Part 17' is the most popular.

What is the average episode length on 7 Minute Security?

The average episode length on 7 Minute Security is 26 minutes.

How often are episodes of 7 Minute Security released?

Episodes of 7 Minute Security are typically released every 6 days, 18 hours.

When was the first episode of 7 Minute Security?

The first episode of 7 Minute Security was released on Feb 1, 2014.

Show more FAQ

Toggle view more icon

Comments