Relaying NTLMv1/v2 - Tradecraft Security Weekly #14

Security Weekly - A CRA Resource
Security Weekly - A CRA Resource
6.7 هزار بار بازدید - 7 سال پیش - A very common attack that
A very common attack that many networks are vulnerable to is called LLMNR or NBT-NS poisoning. Through this attack it is possible to gain access to a user's NTLMv1 or v2 password hash. A more interesting attack can be carried out under the same premise though. Instead of just obtaining a password hash the user's authenticated session to another host can be exploited to run arbitrary code on the server. In this episode of Tradecraft Security Weekly Beau Bullock (@dafthack) shows how to perform this attack using the PowerShell tool Inveigh.
7 سال پیش در تاریخ 1396/05/19 منتشر شده است.
6,791 بـار بازدید شده
... بیشتر