

Episode 128: The Most Common External Pen Test Findings—And How to Fix Them
Mar 21, 2025
The discussion highlights common security findings from external penetration tests, particularly concerning outdated web libraries and plugins like those in WordPress. The hosts review key tools for testing web applications, stressing the importance of manual validation. They delve into web vulnerabilities, emphasizing the impact of cross-site scripting and the necessity of strong security protocols. The conversation also covers how to secure identities in Microsoft 365 and the risks associated with exposing SSH and RDP servers to the internet.
Chapters
Transcript
Episode notes
1 2 3 4 5 6
Intro
00:00 • 3min
Exploring Tools for External Penetration Testing of Web Applications
02:31 • 3min
Navigating Web Vulnerabilities
05:11 • 13min
Securing User Identities in Microsoft 365
18:37 • 9min
Securing SSH and RDP: Risks and Best Practices
27:37 • 5min
Exploring Vulnerabilities in SNMP and External Devices
32:26 • 2min