LBRY Block Explorer

LBRY Claims • def-con-27-marina-simakov-relaying

17be5d8f485635f0920a4b155235e634e1d9d4e6

Published By
Created On
2 Sep 2020 18:55:40 UTC
Transaction ID
Cost
Safe for Work
Free
Yes
DEF CON 27 - Marina Simakov - Relaying Credentials Has Never Been Easier
Active Directory has always been a popular target for attackers, with a constant rise in attack tools attempting to compromise and abuse the main secrets storage of the organization. One of the weakest spots in Active Directory environments lies in the design of one of the oldest authentication protocols - NTLM, which is a constant source of newly discovered vulnerabilities. From CVE-2015-0005, to the recent LDAPS Relay vulnerability, it is clear why this protocol is one of the attackers' favorites.

Although there are offered mitigations such as server signing, protecting the entire domain from NTLM relay is virtually impossible. If it weren't bad enough already, we will present several new ways to abuse this infamous authentication protocol, including a new critical zero-day vulnerability we have discovered which enables to perform NTLM Relay and take over any machine in the domain, even with the strictest security configuration, while bypassing all of today's offered mitigations. Furthermore, we will present why the risks of this protocol are not limited to the boundaries of the on-premises environment and show another vulnerability which allows to bypass various AD-FS restrictions in order to take over cloud resources as well.
...
https://www.youtube.com/watch?v=JoSl5C2HOSc
Author
Content Type
Unspecified
video/mp4
Language
Unspecified
Open in LBRY

More from the publisher

Controlling
VIDEO
BLACK
Controlling
VIDEO
32C3
Controlling
VIDEO
DEF C
Controlling
VIDEO
31C3
Controlling
VIDEO
31C3
Controlling
VIDEO
BLACK
Controlling
VIDEO
DEF C
Controlling
VIDEO
BLACK
Controlling
VIDEO
BLACK