#kerberos — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #kerberos, aggregated by home.social.
-
FreeIPA Flaw Enables Anonymous Clients to Create Admin Credentials
A critical vulnerability in FreeIPA, tracked as CVE-2026-76578, allows an unauthenticated client to create admin credentials by exploiting a chain of defects that lets them create a Kerberos identity and join the administrators group. This flaw, with a preliminary CVSS score of 9.8, was fixed in FreeIPA version…
#FreeipaVulnerability #Kerberos #Cve202676578 #IdentityManagement #AuthenticationBypass
-
🔓 Oh, look! Another #cryptography "wizard" from the ivory tower of academia thinks they can save the world by roasting #Kerberos tickets like marshmallows over a campfire 🔥. Matthew Green, emerging from the cryptographic crypt, offers 1,473 words of ego-stroking drivel about his resume while the rest of us wonder if the true #security threat is death by #boredom. 🥱
https://blog.cryptographyengineering.com/2025/09/10/kerberoasting/ #MatthewGreen #ivorytower #HackerNews #ngated -
Эксперименты с Golden Ticket
Пожалуй, одной из самых опасных и крайне нежелательных сущностей, которые могут завестись в скомпрометированной Windows-инфраструктуре, является Golden Ticket. Это абсолютно легитимный Kerberos-билет, содержащий специально созданные данные, позволяющие злоумышленнику обойти нормальные механизмы проверки и получить высокие привилегии в сети. С помощью золотого билета злоумышленник может получить доступ к любому ресурсу в Active Directory, притворяясь валидным пользователем, без фактической аутентификации. Про Golden Ticket написано уже очень много статей, и аналитики знают, что такую атаку очень сложно обнаружить (большой труд в этом направлении проделали коллеги из R-Vision, рекомендуем к прочтению статью о Golden Ticket ). Не так давно Microsoft выпустила поэтапные обновления безопасности, которые меняют правила использования Golden Ticket. В этой статье мы постараемся разобраться, как обстоят дела с этой атакой сейчас и как Microsoft упростила ее детектирование своими обновлениями. Мы возьмем два инструмента (Mimikatz и Rubeus), сделаем с помощью них Golden Ticket с разными параметрами, а потом попробуем ими воспользоваться и посмотрим, какие сгенерируются события и как отследить их в SOC.
https://habr.com/ru/companies/jetinfosystems/articles/783518/
#kerberos #атака #microsoft #детектирование #mimikatz #rubeus #soc #обновление_безопасности #system #события_журнала
-
Why do I see LM hashes stored in Active Directory?
https://security.stackexchange.com/questions/268083/why-do-i-see-lm-hashes-stored-in-active-directory
#domaincontroller #activedirectory #kerberos #mimikatz #hash -
Also be sure to turn on these monitoring policies in #DefenderForCloudApps so you can #CatchTheHacker before they get too deep, whether you switch to #Kerberos or not. #NetworkSegregation is also a great #LayeredDefense method to ensure if one system is compromised the attacker can't use #SMBtraversal to get to all your computers, globally. #EternalBlue source code is still being used to get to #DCs via #Trikbot evolutions, after #Phishing a user with #LocalAdmin privileges, to execute #mimikatz against #ActiveDirectory to steal all the objects. #YesThisHappened