Ranked #1
Evading Network-Based Detection Mechanisms - Tradecraft Security Weekly #24
Evading Network-Based Detection Mechanisms - Tradecraft Security Weekly #24
In this episode of Tradecraft Security Weekly hosts Beau Bullock (@dafthack) and Mike Felch (@ustayready) discuss method... Read more
29 Mar 2018
•
19mins
Ranked #2
Leaking Windows Creds Externally Via MS Office - Tradecraft Security Weekly #21
Leaking Windows Creds Externally Via MS Office - Tradecraft Security Weekly #21
In this episode of Tradecraft Security Weekly, Mike Felch discusses with Beau Bullock about the possibilities of using f... Read more
1 Dec 2017
•
12mins
Ranked #3
Linux Privilege Escalation - Tradecraft Security Weekly #22
Linux Privilege Escalation - Tradecraft Security Weekly #22
After getting a shell on a server you may or may not have root access. To gain privileged access to a Linux system it ma... Read more
14 Dec 2017
•
17mins
Ranked #4
Google Event Injection - Tradecraft Security Weekly #20
Google Event Injection - Tradecraft Security Weekly #20
Google provides the ability to automatically add events to a calendar directly from emails received by Gmail. This provi... Read more
3 Nov 2017
•
13mins
Ranked #5
HTML5 Storage Exfil via XSS - Tradecraft Security Weekly #23
HTML5 Storage Exfil via XSS - Tradecraft Security Weekly #23
It is fairly common for pentesters to discover Cross-Site Scripting (XSS) vulnerabilities on web application assessments... Read more
8 Jan 2018
•
14mins
Ranked #6
Dissecting XXE Attacks - Tradecraft Security Weekly #19
Dissecting XXE Attacks - Tradecraft Security Weekly #19
When pentesting web services or an application that leverage XML files, XML External Entity (XXE) attacks are a great wa... Read more
25 Sep 2017
•
14mins
Ranked #7
Domain Fronting - Tradecraft Security Weekly #18
Domain Fronting - Tradecraft Security Weekly #18
Domain fronting is a technique used to mask command and control (C2) traffic. It is possible for C2 channels to be proxi... Read more
8 Sep 2017
•
15mins
Ranked #8
Cracking Password Hashes Efficiently - Tradecraft Security Weekly #17
Cracking Password Hashes Efficiently - Tradecraft Security Weekly #17
If you are a penetration tester password cracking is something you will inevitably do. On most engagements we typically ... Read more
1 Sep 2017
•
16mins
Ranked #9
Pivoting Tools Through Meterpreter - Tradecraft Security Weekly #16
Pivoting Tools Through Meterpreter - Tradecraft Security Weekly #16
There are a ton of modules in Metasploit that are extremely useful for performing various attacks post-exploitation. But... Read more
24 Aug 2017
•
11mins
Ranked #10
Identifying Weak Session Tokens Using Entropy - Tradecraft Security Weekly #15
Identifying Weak Session Tokens Using Entropy - Tradecraft Security Weekly #15
Session management in web applications is extremely important in regards to securing user credentials and integrity with... Read more
18 Aug 2017
•
13mins