DNS Recon Redux – Zone Transfers (plus a time machine) for When You Can’t do a Zone Transfer, (Wed, Feb 15th)

When in the recon phase of a security assessment or penetration test, quite often you want to collect the dns names for all hosts in a scope of IP addresses. I covered how to do that with a few different APIs in this story: (https://isc.sans.edu/diary/Using+Passive+DNS+sources+for+Reconnaissance+and+Enumeration/28596)

Continue reading DNS Recon Redux – Zone Transfers (plus a time machine) for When You Can’t do a Zone Transfer, (Wed, Feb 15th)→

Posted in Uncategorized

Venmo Phishing Abusing LinkedIn “slink”, (Mon, Feb 13th)

Recently, I have seen more and more phishing for Venmo credentials. Venmo does use SMS messages as a “second factor” to confirm logins from new devices but does not appear to offer additional robust authentication options. The 4-digit SMS PIN and the lack of additional account security may make Venmo users an attractive target.

Continue reading Venmo Phishing Abusing LinkedIn “slink”, (Mon, Feb 13th)→

Posted in Uncategorized

PCAP Data Analysis with Zeek, (Sun, Feb 12th)

Having full packet captures of a device or an entire network can be extremely useful. It is also a lot of data to go through and process manually. Zeek &#;x26;#;x5b;1&#;x26;#;x5d; can help to simplify network traffic analysis. It can also help save a lot of storage space. I&#;x26;#;39;ll be going through and processing some PCAP data collected from my honeypot. First, we need to install a couple tools to process the PCAP data. I started with a fully updated Ubuntu 22.04.1 LTS desktop &#;x26;#;x5b;2&#;x26;#;x5d;. The steps to get our Zeek data from raw PCAPs will be:

Continue reading PCAP Data Analysis with Zeek, (Sun, Feb 12th)→

Posted in Uncategorized

Obfuscated Deactivation of Script Block Logging, (Fri, Feb 10th)

PowerShell has a great built-in feature called “Script Block Logging”&#;x26;#;x5b;1&#;x26;#;x5d;. It helps to record all activities performed by a script and is a goldmine for incident handlers. That&#;x26;#;39;s the reason why attackers tend to try to disable this feature. There are many ways to achieve this, but I found an interesting one.

Continue reading Obfuscated Deactivation of Script Block Logging, (Fri, Feb 10th)→

Posted in Uncategorized