#kerberos — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #kerberos, aggregated by home.social.
-
Подробная инструкция по настройке Squid 7.5 (Squid proxy, krb+ldap auth, ssl-bump, log in JSON, delay, cache)
Настраивали когда-нибудь Squid? Если да, то вы точно знаете: чтобы всё заработало как надо, приходится лазить по десятку сайтов, форумов и старых гайдов. Кто-то пишет про SSL, кто-то про кэш, кто-то про авторизацию — и всё в разных местах, с разными версиями Для кого эта статья: - Для тех, кто хочет настроить Squid быстро. - Для тех, кто устал искать кусочки информации по всему интернету. - Для тех, кто ценит своё время и любит, когда «работает с первого раза». Эта статья — попытка собрать всё важное в одном месте…
-
🔐 New troubleshooting article: Kerberos authentication can fail across an external Active Directory domain trust when NTLM is disabled, even when SID-History and cross-realm tickets look correct. The post explains how to diagnose 0xC000018B and when Host-to-Realm mapping can help. https://www.sys-manage.com/Blog/kerberos-domain-trust-ntlm-disabled #Kerberos #ActiveDirectory #SysAdmin
-
Apache Kerby, the Java implementation of Kerberos, shipped a fix for CVE-2026-57915: an authentication bypass where an attacker could skip pre-authentication by sending PA-DATA with an unrecognized or unsupported type. The severity is rated important, and the fix is in Kerby 2.1.2. How many Kerberos stacks silently accept PA-DATA types they do not understand, and how many of those are known to operators?
#Kerberos #security -
Как мы забыли согласовать порты и просрочили запуск важного проекта
При внедрении инфраструктурного решения часто кажется, что всё сводится к одному простому действию: открыть доступ к веб-интерфейсу. На первый-третий расчитайсь! Сервер – рас. Администратор – два. URL – три! Открыли HTTPS 443 – значит, можно запускаться. На практике с решениями, которые работают с Linux-каталогом, такой подход всё одно, что бить палкой крапиву. Веб-интерфейс – это только точка управления. Само решение не живёт в вакууме: ему нужно обращаться к контроллерам домена, LDAP-каталогу, Kerberos/KDC, DNS, NTP. И это не пожелания, а обязательная сетевая связность, без которой сервис просто не работает – даже если страница в браузере открывается. Именно поэтому при согласовании с ИБ важно приносить не просьбу «дайте доступ к серверу, сколько не жалко», а схему сетевых взаимодействий. История реальная Проект – Linux-каталог на 600 пользователей. Крайний срок – конец квартала. Мы сделали всё: Linux-каталог развёрнут, тестирование прошло, дата запуска согласована, рубашки заправлены. За день до старта звонит ИБ: «А где схема сетевых взаимодействий?». Схемы нет. Я думал: ну HTTPS же открыли – чего ещё надо? Как оказалось – надо всё остальное. И вот почему. Формально доступ к веб-морде есть. Админ может зайти, логин-пароль ввести. Но само решение не может выполнить ни одной задачи. В каталог ему не пролезть. LDAPS не согласован. Kerberos – только в наших мечтах. DNS – «ну он же работает», но в заявке нет... Я сижу и тупо смотрю на экран. Консоль открыта. Пользователей добавить нельзя.
https://habr.com/ru/articles/1046666/
#linux #ldap #kerberos #activedirectory #aldpro #freeipa #информационнаябезопасность #сетеваяинфраструктура #системноеадминистрирование #внедрение
-
「NTLM」の廃止、「Kerberos」への移行は第2フェイズへ ~Microsoftが発表/「IAKerb」「LocalKDC」が今月にもCanaryチャネルでパブリックプレビュー
https://forest.watch.impress.co.jp/docs/news/2115339.html#forest_watch_impress #Windows_11 #NTLM #Kerberos #IAKerb #LocalKDC #セキュリティ #Windows #インターネット #ネットワーク
-
https://winbuzzer.com/2026/06/07/microsoft-sets-june-kerberos-tests-for-ntlm-shift-xcxwbn/
Microsoft will test Kerberos paths for Windows NTLM fallback in June, giving admins a Canary preview to catch legacy app and device authentication failures.
#WindowsNTLM #Kerberos #Microsoft #MicrosoftWindows #Windows11 #WindowsServer #WindowsInsiderProgram #Cybersecurity #WindowsSecurity
-
https://winbuzzer.com/2026/06/07/microsoft-sets-june-kerberos-tests-for-ntlm-shift-xcxwbn/
Microsoft will test Kerberos paths for Windows NTLM fallback in June, giving admins a Canary preview to catch legacy app and device authentication failures.
#WindowsNTLM #Kerberos #Microsoft #MicrosoftWindows #Windows11 #WindowsServer #WindowsInsiderProgram #Cybersecurity #WindowsSecurity
-
🚨 NTLM is on its way out. Attackers are still abusing it today.
Pass-the-Hash and NTLM relay attacks remain major Active Directory risks.
👉 https://7asecurity.com/blog/2026/05/ntlm-hash-security-kerberos-migration/
-
🚨 Kerberoasting has evolved.
Attackers now blend into normal network traffic with targeted service ticket requests.
Learn how to detect them with KQL hunting and Kerberos hardening.
👉 https://7asecurity.com/blog/2026/05/stop-kerberoasting-threat-hunting-blueprint/
-
Reset — прохождение сложной машины от Tryhackme
Годная машина на тему Windows AD, Kerberos. В начале разведки получаем доступ к гостевой шаре. Оттуда достаем файл с паролем, но не знаем от какой учетной записи. Проводим разведку юзеров, получаем список и находим 1 пользователя к которому подходит этот пароль. Далее проводим разведку с помощью BloodHound и по цепочке получаем доступ к нескольким аккаунтам у последнего есть права Unconstrained Delegation Privilege на доменный компьютер. С помощью механизма S4U2self, запрашиваем билет на имя администратора и захватываем компьютер.
https://habr.com/ru/articles/1041620/
#windows #reset #kerberos #bloodhound #impacket #hashcat #asrep_roasting #delegation #activedirectory #active_directory
-
What is Silver Ticket Attack: A Comprehensive Guide
In this article, I cover how Silver Ticket attacks work, common exploitation scenarios, detection techniques, and mitigation strategies.
https://denizhalil.com/2026/05/27/silver-ticket-attack-comprehensive-guide/#CyberSecurity #ActiveDirectory #SilverTicket #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
What is Silver Ticket Attack: A Comprehensive Guide
In this article, I cover how Silver Ticket attacks work, common exploitation scenarios, detection techniques, and mitigation strategies.
https://denizhalil.com/2026/05/27/silver-ticket-attack-comprehensive-guide/#CyberSecurity #ActiveDirectory #SilverTicket #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Kerbrute: Enumerating Active Directory Accounts
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
🔗 https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/
#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Kerbrute: Enumerating Active Directory Accounts
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
🔗 https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/
#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Basic Active Directory Enumeration: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2025/05/05/basic-active-directory-enumeration-a-comprehensive-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Basic Active Directory Enumeration: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2025/05/05/basic-active-directory-enumeration-a-comprehensive-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
What is Kerberoasting Attack – Kerberoasting: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
What is Kerberoasting Attack – Kerberoasting: A Comprehensive Guide
In this article, I cover how Kerberoasting works, common attack techniques, detection methods, and practical defense strategies.
https://denizhalil.com/2026/05/21/kerberoasting-attack-defense-guide/#CyberSecurity #ActiveDirectory #Kerberoasting #Kerberos #CredentialAccess #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #ThreatDetection #DenizHalil
-
Сквозная аутентификация в Linux: настройка Kerberos, интеграция с браузером и автоматизация через Keytab
Масштабный переход на отечественные ИТ-решения ставит перед системными инженерами и разработчиками задачу глубокого освоения базовых механизмов корпоративной безопасности. В основе современных российских экосистем управления инфраструктурой (таких как ALD Pro на базе Astra Linux) лежит программный комплекс FreeIPA. Главным фундаментом доверия, централизованной авторизации и безопасности в этой экосистеме выступает протокол Kerberos. Его корректное понимание и настройка определяют стабильность работы всех смежных сервисов — от сетевых папок до сложных корпоративных веб-приложений. В этой статье детально разберем «анатомию» Kerberos в среде Linux и покажем, как заставить этот протокол эффективно работать на стыке системного администрирования и веб-разработки. Пройдем полный практический путь, разделенный на несколько логических этапов:
https://habr.com/ru/articles/1036670/
#Kerberos #сквозная_аутентификация #FreeIPA #LDAP #OAuth #беспарольный_вход #ALD_Pro #Astra_Linux #КриптоАРМ_ID #sso
-
💥BATTLE DER GIGANTEN💥
Zwei Figuren aus der griechischen Mythologie treten gegeneinander an und ihr entscheidet wer gewinnt!
Wer ist stärker? Und wieso? Wer hat die fieseren Tricks?Heute:
💖Love vs Wauwau🐶...3...2...1...FIGHT!💥
#daschaosundseinekinder #battledergiganten #olympia #olympischespiele #herz #aphrodite #Götter #tier #Göttin #kampf #wergewinnt #griechischemythologie #chaos #cerberus #zerberos #antike #mythen #kerberos
-
💥BATTLE DER GIGANTEN💥
Zwei Figuren aus der griechischen Mythologie treten gegeneinander an und ihr entscheidet wer gewinnt!
Wer ist stärker? Und wieso? Wer hat die fieseren Tricks?Heute:
💖Love vs Wauwau🐶...3...2...1...FIGHT!💥
#daschaosundseinekinder #battledergiganten #olympia #olympischespiele #herz #aphrodite #Götter #tier #Göttin #kampf #wergewinnt #griechischemythologie #chaos #cerberus #zerberos #antike #mythen #kerberos
-
chromium-browser (104.0.5112.79-1) unstable; urgency=low
We've switched the default search engine from Google to DuckDuckGo.
To manually override it, just go into Settings, click "Search Engine",
and next to "Search engine used in the address bar", select a different
search engine from the pull-down.Also, catching up on a few upstream changes:
#TLSv1 and TLSv1.1 support have been completely dropped from chromium
(as described in https://chromestatus.com/feature/5759116003770368).
Support for CPUs that lack #SSE3 extensions has also been dropped (as
described on
https://www.tomshardware.com/news/chrome-stops-working-on-old-processors).
Most users shouldn't notice, unless you're using older hardware or
"securely" communicating with older hardware.Lastly, #Chromium 101 changed a setting for host-based authentication.
This broke some folks' #Kerberos, among other things. "AuthServerWhitelist"
was renamed to "AuthServerAllowlist", as described in
https://bugs.debian.org/1013268-- Andres Salomon <[email protected]> Tue, 16 Aug 2022 17:29:29 -0400
-
chromium-browser (104.0.5112.79-1) unstable; urgency=low
We've switched the default search engine from Google to DuckDuckGo.
To manually override it, just go into Settings, click "Search Engine",
and next to "Search engine used in the address bar", select a different
search engine from the pull-down.Also, catching up on a few upstream changes:
#TLSv1 and TLSv1.1 support have been completely dropped from chromium
(as described in https://chromestatus.com/feature/5759116003770368).
Support for CPUs that lack #SSE3 extensions has also been dropped (as
described on
https://www.tomshardware.com/news/chrome-stops-working-on-old-processors).
Most users shouldn't notice, unless you're using older hardware or
"securely" communicating with older hardware.Lastly, #Chromium 101 changed a setting for host-based authentication.
This broke some folks' #Kerberos, among other things. "AuthServerWhitelist"
was renamed to "AuthServerAllowlist", as described in
https://bugs.debian.org/1013268-- Andres Salomon <[email protected]> Tue, 16 Aug 2022 17:29:29 -0400
-
Думаем графами с IPAHound
Всем привет, меня зовут Михаил Сухов, я участник команды PT SWARM. Нам в команде все чаще встречается инфраструктура, построенная на базе альтернативных реализаций службы каталога Microsoft Active Directory. Одной из таких реализаций, заслуженно получившей большое распространение является FreeIPA. В ходе работы с FreeIPA стало очевидно, что можно изучать еще и архитектурные особенности, которые сильно отличаются от AD. Так появился IPAHound — наш аналог BloodHound для FreeIPA. За основу был взят проект BloodHound Legacy с поддержкой PKI. Мы неоднократно использовали IPAHound в своих проектах по поиску уязвимостей. В этой статье я расскажу о нашем инструменте. Также посмотрим на различные способы анализа связей, облегчающие продвижение в FreeIPA.
https://habr.com/ru/companies/pt/articles/1028412/
#ipahound #freeipa #ldap #sudo #selinux #kerberos #pentest #ald pro #bloodhound
-
Самое подробное руководство по использованию утилиты ktpass в среде Active Directory
Давайте разберем как с помощью утилиты ktpass.exe создавать гарантированно рабочие файлы keytab . Подробно и с примерами рассмотрим каждый параметр утилиты ktpass.exe . А самое интересное - вы узнаете неочевидные факты о принципах использовании salt при генерации ключей Kerberos, из-за которой получаются нерабочие ключи AES. В этом поможет инспекция базы ntds.dit командлетами DSInternals.
-
Интеграция MULTIDIRECTORY и MULTIFACTOR: двухфакторная аутентификация в Kerberos
Kerberos — один из тех протоколов, которые в инфраструктуре работают «тихо». Пользователь вошёл в систему один раз, и дальше всё открывается без лишних вопросов. За этим удобством стоит строгая модель доверия, построенная вокруг KDC и тикетов. Но есть нюанс: классический Kerberos — это по сути однофакторная аутентификация. Если пароль скомпрометирован, вся цепочка доверия находится под угрозой. В этой статье разберём, как можно усилить Kerberos с помощью второго фактора и как это реализовано в связке MULTIDIRECTORY и MULTIFACTOR.
https://habr.com/ru/companies/multifactor/articles/1027480/
#multidirectory #multifactor #kerberos #2fa #2faаутентификация #служба_каталогов #мультифактор
-
@abbra and I released version 0.1.0 of the Kirmes LocalKDC today.
https://gitlab.com/kirmes/localkdc/-/releases/0.1.0
Wait, what are we needing a KDC for which only runs locally? Well, you want the details, I suggest to watch our talk at https://sambaxp.org/ next Monday (or wait till it is online).
It uses systemd-userdb via libkirmes (written in rust) and implements KDB modules for MIT Kerberos also written in Rust (kurbu5)!
-
@abbra and I released version 0.1.0 of the Kirmes LocalKDC today.
https://gitlab.com/kirmes/localkdc/-/releases/0.1.0
Wait, what are we needing a KDC for which only runs locally? Well, you want the details, I suggest to watch our talk at https://sambaxp.org/ next Monday (or wait till it is online).
It uses systemd-userdb via libkirmes (written in rust) and implements KDB modules for MIT Kerberos also written in Rust (kurbu5)!
-
Особенность настройки аутентификации 1С через веб-сервер расположенный на Linux
В сети достаточно информации о настройке аутентификации 1С при публикации базы на веб‑сервере. Наиболее полная из найденных расположена по адресу https://infostart.ru/1c/articles/2440678 Информация в комментариях к статье достойна ознакомления. Однако для сценария когда: Подробнее...
-
Никаких эксплойтов и zero-day: как эксплуатация безобидных настроек Асtive Directory приводит к компрометации домена
Привет, Хабр! На связи Дмитрий Неверов, технический консультант направления тестирования внутренней инфраструктуры команды Бастиона и автор книги «Идём по киберследу» . Пентестер зачастую воспринимается как «белый маг хакер», которому дай только возможность запустить пару эксплойтов и поэксплуатировать zero-day. Однако наш опыт подсказывает, что самые неприметные и «безобидные» настройки Active Directory могут нести не меньшую опасность в руках умелого взломщика. В этой статье я расскажу о трех интересных пентестах, выполненных нашей командой. Во всех этих кейсах использовалась моя базовая методология пентеста, которая несколько отличается от классического подхода, и применялись только этичные приемы. Итак, поехали!
https://habr.com/ru/companies/bastion/articles/1012354/
#active_directory #Red_Team #пентест #информационная_безопасность #тестирование_на_проникновение #Kerberos #AD #компрометация_домена
-
Типичные ошибки настройки Active Directory
Всем привет! На связи Карпенко Савелий, специалист по тестированию на проникновение из группы по борьбе с уязвимостями в компании ТехВилл. В рамках нашей работы мы регулярно тестируем Active Directory (AD). Это центральный сервис аутентификации и управления доступом во многих корпоративных сетях. С практической точки зрения ошибки в конфигурациях AD часто становятся главной причиной взлома, среди проблемных аспектов можно назвать неверное назначение прав, доступов и использование устаревших механизмов аутентификации. Наличие недостатков в конфигурациях даёт атакующему возможность последовательно поднимать уровень своих привилегий. Ниже собраны типовые ошибки конфигурации, которые чаще всего встречаются на проектах, и показано, как они складываются в цепочки компрометации. На практике аудит и тестирование обычно начинаются с исходных учетных данных, которые предоставляет заказчик. Если их нет, проникновение в инфраструктуру часто происходит через внешние веб-сервисы и ошибки на периметре (утечки паролей, небезопасные публикации, уязвимости бизнес-приложений). В российской практике одним из наиболее частых векторов для входа считается инфраструктура 1С, из-за повсеместного использования и различного уровня поддержки здесь чаще встречаются и слабые настройки, и типовые уязвимости.
https://habr.com/ru/companies/vkusvill/articles/1010812/
#вкусвилл #active_directory #тестирование #kerberos #windows #pentest
-
Today's fun discovery:
* if you set the `+needchange` flag on a user's #Kerberos principal, the command-line utilities all do the right thing
* in my experience, the same is true of `pam_krb5` when it's configured to be first in the authentication stack
* but if you also have pam_duo configured, it will fight with pam_krb5 and both will fail, locking the user out rather than allowing them to change their passwordI haven't figured out how to test this with another 2fa module yet.
-
Today's fun discovery:
* if you set the `+needchange` flag on a user's #Kerberos principal, the command-line utilities all do the right thing
* in my experience, the same is true of `pam_krb5` when it's configured to be first in the authentication stack
* but if you also have pam_duo configured, it will fight with pam_krb5 and both will fail, locking the user out rather than allowing them to change their passwordI haven't figured out how to test this with another 2fa module yet.
-
Got some progress with protocol transition in #OpenSSH: if you login with any authentication mechanism that does not lead to creation of #Kerberos tickets, now you can configure your server to generate one on the user's behalf. This uses Services For User (S4U) extensions available in Active Directory and #FreeIPA implementations. There are few issues we still trying to address (and bugs found during this development) but it looks promising.
Couple demos in the next toots: -
Got some progress with protocol transition in #OpenSSH: if you login with any authentication mechanism that does not lead to creation of #Kerberos tickets, now you can configure your server to generate one on the user's behalf. This uses Services For User (S4U) extensions available in Active Directory and #FreeIPA implementations. There are few issues we still trying to address (and bugs found during this development) but it looks promising.
Couple demos in the next toots: -
PSA for #Qutebrowser users (#Qt6 #Webengine based): we need to use this option to enable #kerberos support in `~/.config/qutebrowser/autoconfig.yaml` (for example, if you're a @fedora package maintainer and don't want to have to keep re-logging into Fedora websites):
```
qt.args:
global:
- auth-server-allowlist=*<domain>
```Used to be `auth-server-whitelist` but changed at some point.
Reference: https://github.com/qutebrowser/qutebrowser/issues/8313
-
Problemy NTLM: drugie starcie. Wymuszenie uwierzytelnienia NTLM
Wstęp W poprzednim artykule poświęconym NTLM, rozebraliśmy na czynniki pierwsze podstawowe pojęcia: czym jest NetNTLM a czym hash NT, jak można przeprowadzić ataki polegające na przechwyceniu challenge NetNTLM oraz na czym polegają podatności typu relay. Jeżeli powyższe pojęcia nie są dla Ciebie zrozumiałe, to przed przystąpieniem do dalszej lektury, koniecznie...
#Aktualności #Teksty #ActiveDirectory #Coercion #Kerberos #Ntlm #Windows
https://sekurak.pl/problemy-ntlm-drugie-starcie-wymuszenie-uwierzytelnienia-ntlm/
-
Problemy NTLM: drugie starcie. Wymuszenie uwierzytelnienia NTLM
Wstęp W poprzednim artykule poświęconym NTLM, rozebraliśmy na czynniki pierwsze podstawowe pojęcia: czym jest NetNTLM a czym hash NT, jak można przeprowadzić ataki polegające na przechwyceniu challenge NetNTLM oraz na czym polegają podatności typu relay. Jeżeli powyższe pojęcia nie są dla Ciebie zrozumiałe, to przed przystąpieniem do dalszej lektury, koniecznie...
#Aktualności #Teksty #ActiveDirectory #Coercion #Kerberos #Ntlm #Windows
https://sekurak.pl/problemy-ntlm-drugie-starcie-wymuszenie-uwierzytelnienia-ntlm/
-
@vermaden has shared an insightful article about 𝗡𝗮𝘁𝗶𝘃𝗲 𝗙𝗿𝗲𝗲𝗕𝗦𝗗 𝗞𝗲𝗿𝗯𝗲𝗿𝗼𝘀/𝗟𝗗𝗔𝗣 𝘄𝗶𝘁𝗵 𝗙𝗿𝗲𝗲𝗜𝗣𝗔/𝗜𝗗𝗠
Go read learn
#Kerberos #freeBSD #BSD #programming #technology #networking #LDAP #FreeIPA #IDM #reading
https://vermaden.wordpress.com/2026/02/18/native-freebsd-kerberos-ldap-with-freeipa-idm/
-
New 𝗡𝗮𝘁𝗶𝘃𝗲 𝗙𝗿𝗲𝗲𝗕𝗦𝗗 𝗞𝗲𝗿𝗯𝗲𝗿𝗼𝘀/𝗟𝗗𝗔𝗣 𝘄𝗶𝘁𝗵 𝗙𝗿𝗲𝗲𝗜𝗣𝗔/𝗜𝗗𝗠 article based on @Larvitz work - credit goes to him.
https://vermaden.wordpress.com/2026/02/18/native-freebsd-kerberos-ldap-with-freeipa-idm/
-
Kerberos zastąpi NTLM w najnowszych systemach Windows. Jak się przygotować?
Już od dawna panuje przekonanie,To już ponad 30 lat, odkąd Microsoft wprowadził protokół NTLM (New Technology LAN Manager) służący do uwierzytelniania użytkowników w systemach Windows. I choć nadal cieszy się on dużą popularnością (nawet w najnowszych wersjach systemów Windows spotkamy ten mechanizm uwierzytelnienia) to zdaje się, że jego dni zostały...
#WBiegu #Kerberos #Microsoft #Ntlm #Windows
https://sekurak.pl/kerberos-zastapi-ntlm-w-najnowszych-systemach-windows-jak-sie-przygotowac/
-
🔐 Kerberos protege la autenticación en redes empresariales sin enviar contraseñas. Conoce cómo funciona este protocolo esencial en ciberseguridad 🖥️
Lee más 👉 https://www.soloingenieria.org/ingenieria-en-sistemas-computacionales/kerberos/
Imagen creada con IA.
#Kerberos #SeguridadInformática #ActiveDirectory #ProtocolosDeRed #Ciberseguridad #IngenieríaDeSistemas -
💡 Si administras redes con Active Directory, verifica que Kerberos esté correctamente configurado. Es tu primera línea de defensa contra ataques de suplantación de identidad.
#Kerberos #SeguridadInformática #ActiveDirectory #ProtocolosDeRed #Ciberseguridad #IngenieríaDeSistemas
-
Microsoft setzt auf Kerberos: NTLM-Authentifizierung wird in Windows abgeschaltet
NTLM weist nach heutigen Standards mehrere Defizite auf:
-
https://winbuzzer.com/2026/02/02/microsoft-disable-ntlm-default-windows-kerberos-xcxwbn/
Microsoft to Disable NTLM Protocol by Default in Future Windows Releases
#Microsoft #WindowsServer #Windows11 #Windows #OperatingSystems #NTLM #Kerberos #Authentication #Security #Cybersecurity #SecurityFlaws #SecurityThreats
-
Detection of Kerberos Golden Ticket Attacks via Velociraptor: https://detect.fyi/detection-of-kerberos-golden-ticket-attacks-via-velociraptor-cfe7cc26d3eb
-
Microsoft anuncia que antes de finalizar este año, eliminarán el protocolo de autenticación NTLM ¿Cómo deben prepararse los administradores de TI ante este escenario?
-
If you have a third-party device that doesn't support AES-SHA1, reach out to [email protected] with information about the device and scenario.
-
#Microsoft startet mit Identifizierung von unsicherer #RC4-Verschlüsselung | Security https://www.heise.de/news/Microsoft-startet-mit-Identifizierung-von-unsicherer-RC4-Verschluesselung-11145332.html #Kerberos #patchday