Testing G Suites with MailSniper
E3

Testing G Suites with MailSniper

Join us in the Black Hills InfoSec Discord server here: https://discord.gg/BHIS to keep the security conversation going! 

Reach out to Black Hills Infosec if you need pentesting, threat hunting, ACTIVE SOC, incident response, or blue team services -- https://www.blackhillsinfosec.com/ 

Chapters
  • (00:00) - Intro
  • (01:00) - Overview
  • (02:48) - Email
  • (09:15) - Google Capture
  • (13:36) - Duo TwoFactor
  • (16:15) - Proxy Cannon
  • (17:56) - SOCAT
  • (18:39) - Demo
  • (22:28) - Password Spraying
  • (26:47) - Invoke Username Harvest
  • (28:56) - Invoke Spray Gmail
  • (34:16) - PowerShell Oneliner
  • (35:47) - MailSniper Repository
  • (36:40) - Tools for Metadata
  • (38:40) - PowerMeta
  • (39:20) - SSO
  • (40:53) - Google API
  • (41:26) - Does MailSniper work with Office365
  • (42:32) - Does MailSniper work with G Suites
  • (44:18) - Will Microsoft shut down GitHub

Join Matt Toussain as he talks about Mailsniper, a tool written by our very own Beau Bullock. Wouldn't you like to START your pen tests knowing every username for all the individuals in your target environment? Gmail, G Suite, Outlook Web Access, Exchange Web Services... Email. A divine gift issued to hackers with no statute of limitations. In this webcast, we explore an exploitation workflow using new features of the MailSniper toolkit testing G Suite. 

In addition to leveraging G Suites as an Information disclosure engine, we explore the signaling involved with the Google Accounts authentication API. This allows us to observe and bypass protections Google attempts to implement such as Captchas and even 2FA. We close out with a demonstration of mass account enumeration and password guessing attacks!

Slides available here: https://www.blackhillsinfosec.com/webcast-testing-g-suites-with-mailsniper/ 

Black Hills Infosec Socials 
Twitter: https://twitter.com/BHinfoSecurity 
Mastodon: https://infosec.exchange/@blackhillsinfosec 
LinkedIn: https://www.linkedin.com/company/antisyphon-training 
Discord: https://discord.gg/bhis
 
Black Hills Infosec Shirts & Hoodies 
https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections 
 
Black Hills Infosec Services 
Active SOC: https://www.blackhillsinfosec.com/services/active-soc/ 
Penetration Testing: https://www.blackhillsinfosec.com/services/ 
Incident Response: https://www.blackhillsinfosec.com/services/incident-response/ 
 
Backdoors & Breaches - Incident Response Card Game 
Backdoors & Breaches: https://www.backdoorsandbreaches.com/ 
Play B&B Online: https://play.backdoorsandbreaches.com/ 
 
Antisyphon Training 
Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/ 
Live Training: https://www.antisyphontraining.com/course-catalog/ 
On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/ 
 
Educational Infosec Content 
Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ 
Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest 
Active Countermeasures YouTube: https://youtube.com/activecountermeasures 
Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining 

Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/ 

#bhis  #infosec

Episode Video