Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @YaronZi
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @YaronZi
-
Prikvačeni tweet
The
@defcon talk I gave with@simakov_marina on#NTLM relay is now available online! https://youtu.be/vIISsfLh4iM If you haven't seen it live and you're interested in#ActiveDirectory security you should definitely check it out!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
This is how we start the week! What about you? BsidesTLV 2020 CFP is open https://cfp.bsidestlv.com/20/cfp Submit and share.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I'm happy to share that the talk I've submitted with
@simakov_marina "Advanced Credential Relaying Techniques and How to Thwart Them" got accepted to@WEareTROOPERS. You don't want to miss this talk if you're interested with what is the latest in#NTLM relay...Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
We're seeking a Senior Software Backend Developer in our Ramat Gan office (Tel Aviv, Israel). Come join our team! https://hubs.ly/H0m9c6f0
#softwaredeveloper#softwarejobs#hiring#careersHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
You can use the free AD hygiene tool
#PreemptLite to analyze your network and discover all machines which don't enforce SMB signing. Enforcing SMB signing on DCs alone (which is the default config) is not enough. https://www.preempt.com/preempt-platform/preempt-lite/ …https://twitter.com/byt3bl33d3r/status/1195064478225911809 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
@TalBeerySec was accurate:https://twitter.com/TalBeerySec/status/1138528948114116613 …#NTLM is a pig...Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
There seems to be yet another
#NTLM Relay issue with how NETLOGON messages are validated. https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1384 … (discovered by@DanyalDrew) will allow(?) users to relay NTLM to DCs like with https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1019 …. Waiting for a blog with technical details@elad_shamirPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Even though more than two years had passed, this is still a relevant attack vector...https://twitter.com/DirectoryRanger/status/1192332110507450368 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
[Blog] Office 365 was vulnerable to network attacks due to a vulnerability in Microsoft Teams. Here's a demo of an attacker obtaining access to all emails and OneDrive/SharePoint files if the victim joins an attacker controlled network. Details: https://dirkjanm.io/office-365-network-attacks-via-insecure-reply-url/ …pic.twitter.com/jqwcil2KwD
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
@_dirkjan not sure if you've noticed this. You'll definitely like it...
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Two new vulnerabilities in NTLM. 1. Allowing attacker to drop the MIC (again!) and relay SMB session credentials. 2. Relaying sessions with LMv2 reaponses. If exploited, these can lead to account/domain compromise. https://www.preempt.com/blog/drop-the-mic-2-active-directory-open-to-more-ntlm-attacks/ … .
@simakov_marina@preemptsecurityPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
Just merged
@buffaloverflow PR into master. Nice feature, thanks a lot Rich!https://twitter.com/buffaloverflow/status/1178744119054815232 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
Just tagged a new stable impacket (0.9.20) version. Python 3.x support added (tested in 3.6). More info & download: https://www.secureauth.com/labs/open-source-tools/impacket … andhttps://github.com/SecureAuthCorp/impacket/releases/tag/impacket_0_9_20 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
After issuing an advisory to turn on LDAP signing & channel binding,
#Microsoft is changing the default configuration (starting January 2020) to enable those settings. Really excited about this change! Especially after our latest NTLM Relay talks https://support.microsoft.com/en-us/help/4520412/2020-ldap-channel-binding-and-ldap-signing-requirement-for-windows …@YaronZiHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
Seems Microsoft is finally taking a stance against NTLM relaying to LDAP, by enforcing LDAP signing and channel binding by default starting January 2020. This is a big and important change to improve AD security, especially from a network point of view!https://twitter.com/qd285/status/1171764100680036352 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
Did you know: 1. Computer objects in AD can be added to the local admins group on other computers. 2. NT AUTHORITY\SYSTEM authenticates to other systems as the AD computer principal 3. Privileged computer accounts are VERY common, and typically overlooked.
#BloodHound basicspic.twitter.com/N7NNkyQ2Ez
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
Note that remote code execution is possible when SMB signing is disabled. Ex: Exchange Servers(ES) are often admins on each other. Attacker coerces one ES to auth to the attacker(e.g. w/SpoolSample) and the attacker NTLM relays to the other ES. I've exploited this more than once.https://twitter.com/_wald0/status/1167550622851190784 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
Muscular Dystrophy killed my mother, her brother, and her father. Now it's killing my sister. Here's my ask: if you have benefited from
#BloodHound, don't buy me a beer. Instead, donate whatever amount you can to MDA using this link:https://mda.donordrive.com/index.cfm?fuseaction=donorDrive.team&teamID=5703 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yaron Zinar proslijedio/la je Tweet
If you weren’t in Vegas for
#BHUSA and#DEFCON,@YaronZi and I will be presenting the results of our NTLM research in a webinar this Tuesday, everyone is welcome, Q&A at the end included
https://www.preempt.com/events/webinar-how-we-bypassed-all-ntlm-relay-mitigations/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV190023 … great to see
#microsoft is taking action to reduce#NTLM attack surface by advising customers to enable LDAP relay mitigations. We talked about these issues at our@defcon and@BlackHatEvents talks.@simakov_marinaHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.