#ntlm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ntlm, aggregated by home.social.
-
Great news! go-mail v0.8.0 has just been released and it's a biggie! This release adds native NTLMv2 and DKIM support as well as bunch of cool improvements and fixes. Thanks to everybody who contributed to this release!
-
Great news! go-mail v0.8.0 has just been released and it's a biggie! This release adds native NTLMv2 and DKIM support as well as bunch of cool improvements and fixes. Thanks to everybody who contributed to this release!
-
Great news! go-mail v0.8.0 has just been released and it's a biggie! This release adds native NTLMv2 and DKIM support as well as bunch of cool improvements and fixes. Thanks to everybody who contributed to this release!
-
It took some time, but it's finally working...
go-mail v0.8.0 (release planned in the next few days) will add native NTMLv2 SMTP authentication support (without any 3rd party library dependency).
I couldn't have done this without the absolute fantastic documentation of the cURL project: https://curl.se/rfc/ntlm.html
Thanks @bagder for providing this. It saved me so much time!
-
It took some time, but it's finally working...
go-mail v0.8.0 (release planned in the next few days) will add native NTMLv2 SMTP authentication support (without any 3rd party library dependency).
I couldn't have done this without the absolute fantastic documentation of the cURL project: https://curl.se/rfc/ntlm.html
Thanks @bagder for providing this. It saved me so much time!
-
Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now.
#NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec
-
Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now.
#NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec
-
GNU SASL 2.2.4 closes a heap-disclosure flaw (CWE-908, CVSS 6.5 as claimed) in _gsasl_ntlm_client_step: the code allocated a fixed 1,076-byte structure with malloc rather than calloc, then accepted short Type-2 challenges from the server, leaving roughly 1,060 uninitialized bytes that get echoed back in the client response. Versions 2.2.3 and earlier linked against libntlm are affected. Should NTLM still be reachable in new deployments at all?
#security #NTLM -
「NTLM」の廃止、「Kerberos」への移行は第2フェイズへ ~Microsoftが発表/「IAKerb」「LocalKDC」が今月にもCanaryチャネルでパブリックプレビュー
https://forest.watch.impress.co.jp/docs/news/2115339.html#forest_watch_impress #Windows_11 #NTLM #Kerberos #IAKerb #LocalKDC #セキュリティ #Windows #インターネット #ネットワーク
-
「NTLM」の廃止、「Kerberos」への移行は第2フェイズへ ~Microsoftが発表/「IAKerb」「LocalKDC」が今月にもCanaryチャネルでパブリックプレビュー
https://forest.watch.impress.co.jp/docs/news/2115339.html#forest_watch_impress #Windows_11 #NTLM #Kerberos #IAKerb #LocalKDC #セキュリティ #Windows #インターネット #ネットワーク
-
「NTLM」の廃止、「Kerberos」への移行は第2フェイズへ ~Microsoftが発表/「IAKerb」「LocalKDC」が今月にもCanaryチャネルでパブリックプレビュー
https://forest.watch.impress.co.jp/docs/news/2115339.html#forest_watch_impress #Windows_11 #NTLM #Kerberos #IAKerb #LocalKDC #セキュリティ #Windows #インターネット #ネットワーク
-
Fin de NTLM : IAKerb et LocalKDC arrivent en préversion sur Windows https://www.it-connect.fr/fin-de-ntlm-iakerb-et-localkdc-arrivent-en-preversion-sur-windows/ #Logiciel-OS #Microsoft #Windows #NTLM
-
Fin de NTLM : IAKerb et LocalKDC arrivent en préversion sur Windows https://www.it-connect.fr/fin-de-ntlm-iakerb-et-localkdc-arrivent-en-preversion-sur-windows/ #Logiciel-OS #Microsoft #Windows #NTLM
-
Responder Tool for Network Credential Capture in Active Directory
In this article, I cover how Responder works, common credential capture techniques, and practical mitigation strategies for defending Active Directory environments.
https://denizhalil.com/2026/05/18/responder-tool-active-directory-credential-capture/
#CyberSecurity #ActiveDirectory #Responder #LLMNR #NTLM #CredentialCapture #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #EthicalHacking #DenizHalil
-
Responder Tool for Network Credential Capture in Active Directory
In this article, I cover how Responder works, common credential capture techniques, and practical mitigation strategies for defending Active Directory environments.
https://denizhalil.com/2026/05/18/responder-tool-active-directory-credential-capture/
#CyberSecurity #ActiveDirectory #Responder #LLMNR #NTLM #CredentialCapture #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #EthicalHacking #DenizHalil
-
Responder Tool for Network Credential Capture in Active Directory
In this article, I cover how Responder works, common credential capture techniques, and practical mitigation strategies for defending Active Directory environments.
https://denizhalil.com/2026/05/18/responder-tool-active-directory-credential-capture/
#CyberSecurity #ActiveDirectory #Responder #LLMNR #NTLM #CredentialCapture #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #EthicalHacking #DenizHalil
-
Включаем EPA в FreeTDS и go-mssqldb: приключение на 5 минут
Представьте: вы теряете контроль над SCCM — одним из самых критичных инструментов управления инфраструктурой. А точкой входа становится обычное подключение к MSSQL, где он хранит свои данные. Злоумышленник перехватывает NTLM-аутентификацию и перенаправляет её на нужный сервер — так работает NTLM relay. Мы в команде Security Engineering решили не ждать эксплуатации этой уязвимости. Меня зовут Булат Гафуров, я инженер по информационной безопасности в Яндексе. В этой статье я расскажу, почему стандартного решения оказалось недостаточно и как мы добавили поддержку механизма EPA в популярные библиотеки, чтобы переключить защиту на стороне MSSQL в режим Require, не лишив Linux- и Windows-сервисы доступа к данным.
https://habr.com/ru/companies/yandex/articles/1031368/
#windows #security #ntlm_relay #ntlm #ntlmrelay #epa #mssql #mssqlserver #microsoft #freetds
-
----------------
🔎 AI: Integrating LLMs into Offensive Security Workflows
Summary
This blog outlines practical integration of large language models into offensive security engagements. Authors describe improving public proof‑of‑concept Model Context Protocol (MCP) servers for BloodHound and Burp Suite to support real‑world testing, and present LLM CLI usage patterns that enable agentic execution across reconnaissance, data enrichment, attack chaining, and reporting.
Technical specifics
• MCP servers: Existing MCP server projects for BloodHound and Burp Suite were adapted to work in offensive engagements, enabling LLMs to fetch, query, and reason over structured data such as Active Directory graphs and proxied web traffic.
• LLM CLI agents: Modern CLIs (examples cited include Gemini CLI, Claude Code, and OpenAI’s Codex) shift models from single‑shot responders to autonomous operators capable of chaining actions: run a tool, parse output, decide next steps, and continue until objectives are met.
• Example capabilities: An LLM connected to an AD graph via a MCP server can rapidly enumerate privilege escalation paths that would otherwise require hours of manual review. When paired with Burp Suite MCP, LLMs can correlate requests/responses across sessions to accelerate vulnerability triage. The authors also describe an NTLM relaying Gemini extension that demonstrates chaining of attack steps.Operational characteristics
• Scope of access: An LLM CLI can operate on any tool or artifact the host environment exposes—OS utilities, custom scripts, open‑source offensive tooling, and locally hosted services—then interpret outputs to guide successive actions.
• Agentic execution model: Gemini’s agentic design emphasizes iterative, feedback‑driven workflows where the model determines subsequent commands based on intermediate results rather than relying on a single prompt.What was demonstrated
• Improved MCP integrations for BloodHound and Burp Suite adapted from public proof‑of‑concept servers.
• A proof‑of‑concept Gemini extension automating NTLM relay orchestration.
• Use cases spanning AD privilege path identification, web traffic correlation, automated triage, and multi‑step attack choreography.Limitations & considerations (as presented)
• The writeup focuses on capabilities and demonstrated integrations; implementation specifics and environmental constraints are described at a conceptual level. The examples show how LLMs can reduce manual effort and expand coverage when granted appropriate tool access.🔹 llm #mcp #bloodhound #burpsuite #ntlm
-
NTLM relay attacks haven't died. They evolved.
Abusing SamrSetInformationUser in AD lets attackers set empty passwords on accounts without triggering standard password change alerts. Classic protocol weakness, new exploitation path.
The attack surface doesn't shrink when protocols are deprecated. It shifts to adjacent trust relationships.
-
NTLM relay attacks haven't died. They evolved.
Abusing SamrSetInformationUser in AD lets attackers set empty passwords on accounts without triggering standard password change alerts. Classic protocol weakness, new exploitation path.
The attack surface doesn't shrink when protocols are deprecated. It shifts to adjacent trust relationships.
-
Problemy NTLM: drugie starcie. Wymuszenie uwierzytelnienia NTLM
Wstęp W poprzednim artykule poświęconym NTLM, rozebraliśmy na czynniki pierwsze podstawowe pojęcia: czym jest NetNTLM a czym hash NT, jak można przeprowadzić ataki polegające na przechwyceniu challenge NetNTLM oraz na czym polegają podatności typu relay. Jeżeli powyższe pojęcia nie są dla Ciebie zrozumiałe, to przed przystąpieniem do dalszej lektury, koniecznie...
#Aktualności #Teksty #ActiveDirectory #Coercion #Kerberos #Ntlm #Windows
https://sekurak.pl/problemy-ntlm-drugie-starcie-wymuszenie-uwierzytelnienia-ntlm/
-
Problemy NTLM: drugie starcie. Wymuszenie uwierzytelnienia NTLM
Wstęp W poprzednim artykule poświęconym NTLM, rozebraliśmy na czynniki pierwsze podstawowe pojęcia: czym jest NetNTLM a czym hash NT, jak można przeprowadzić ataki polegające na przechwyceniu challenge NetNTLM oraz na czym polegają podatności typu relay. Jeżeli powyższe pojęcia nie są dla Ciebie zrozumiałe, to przed przystąpieniem do dalszej lektury, koniecznie...
#Aktualności #Teksty #ActiveDirectory #Coercion #Kerberos #Ntlm #Windows
https://sekurak.pl/problemy-ntlm-drugie-starcie-wymuszenie-uwierzytelnienia-ntlm/
-
Podstawowe problemy bezpieczeństwa NTLM
W świecie nowoczesnych technologii chmurowych, uwierzytelniania wieloskładnikowego i architektury Zero Trust, łatwo zapomnieć o fundamentach, na których wciąż stoi większość firmowych sieci wewnętrznych. Mowa o środowiskach Active Directory i protokołach, które pamiętają czasy Windows NT. Jednym z takich reliktów, który pozostaje jednym z najpopularniejszych wektorów ataku podczas wewnętrznych testów penetracyjnych,...
-
Podstawowe problemy bezpieczeństwa NTLM
W świecie nowoczesnych technologii chmurowych, uwierzytelniania wieloskładnikowego i architektury Zero Trust, łatwo zapomnieć o fundamentach, na których wciąż stoi większość firmowych sieci wewnętrznych. Mowa o środowiskach Active Directory i protokołach, które pamiętają czasy Windows NT. Jednym z takich reliktów, który pozostaje jednym z najpopularniejszych wektorów ataku podczas wewnętrznych testów penetracyjnych,...
-
NTLM для хакера. Подробное описание работы и безопасности протокола
Привет, мир! Недавно я решил пополнить свои знания протоколов NTLM'ом; и, к большому сожалению, стоящих материалов, которые бы подробно и полно описывали работу NTLM, я не нашел (есть лишь пара годных статей на английском языке, но и они, на мой взгляд, не дают нужного уровня глубины). Потому я решил написать статью, которая бы в подробностях рассказала о том, как работает данный протокол и удовлетворила даже самого душного нерда, каким автор и является))) Изучить матчасть
https://habr.com/ru/articles/993934/
#NTLM #ntlmrelay #безопасность #сетевая_безопасность #администрирование_сетей #сетевые_протоколы #аутентификация #информационная_безопасность
-
Kerberos zastąpi NTLM w najnowszych systemach Windows. Jak się przygotować?
Już od dawna panuje przekonanie,To już ponad 30 lat, odkąd Microsoft wprowadził protokół NTLM (New Technology LAN Manager) służący do uwierzytelniania użytkowników w systemach Windows. I choć nadal cieszy się on dużą popularnością (nawet w najnowszych wersjach systemów Windows spotkamy ten mechanizm uwierzytelnienia) to zdaje się, że jego dni zostały...
#WBiegu #Kerberos #Microsoft #Ntlm #Windows
https://sekurak.pl/kerberos-zastapi-ntlm-w-najnowszych-systemach-windows-jak-sie-przygotowac/
-
Kerberos zastąpi NTLM w najnowszych systemach Windows. Jak się przygotować?
Już od dawna panuje przekonanie,To już ponad 30 lat, odkąd Microsoft wprowadził protokół NTLM (New Technology LAN Manager) służący do uwierzytelniania użytkowników w systemach Windows. I choć nadal cieszy się on dużą popularnością (nawet w najnowszych wersjach systemów Windows spotkamy ten mechanizm uwierzytelnienia) to zdaje się, że jego dni zostały...
#WBiegu #Kerberos #Microsoft #Ntlm #Windows
https://sekurak.pl/kerberos-zastapi-ntlm-w-najnowszych-systemach-windows-jak-sie-przygotowac/
-
Microsoft desactivará NTLM por defecto para una autenticación más segura https://blog.elhacker.net/2026/02/microsoft-desactivara-ntlm-por-defecto.html #ciberseguridad #autenticación #protocolo #seguridad #Windows #NTLM
-
Microsoft desactivará NTLM por defecto para una autenticación más segura https://blog.elhacker.net/2026/02/microsoft-desactivara-ntlm-por-defecto.html #ciberseguridad #autenticación #protocolo #seguridad #Windows #NTLM
-
#Windows :windows: mit #NTLM: Das Ende des Albtraums – vielleicht demnächst | Security https://www.heise.de/news/Windows-Microsoft-konkretisiert-NTLM-Aus-nennt-aber-immer-noch-kein-Datum-11162674.html #Microsoft
-
#Windows :windows: mit #NTLM: Das Ende des Albtraums – vielleicht demnächst | Security https://www.heise.de/news/Windows-Microsoft-konkretisiert-NTLM-Aus-nennt-aber-immer-noch-kein-Datum-11162674.html #Microsoft
-
「NTLM」は既定で無効に ~Microsoftが3ステップにわたる移行フェイズを開始/全バージョン非推奨、「Kerberos」への移行を
https://forest.watch.impress.co.jp/docs/news/2082915.html#forest_watch_impress #NTLM #セキュリティ #Windows #システム_ファイル #システム
-
https://winbuzzer.com/2026/02/02/microsoft-disable-ntlm-default-windows-kerberos-xcxwbn/
Microsoft to Disable NTLM Protocol by Default in Future Windows Releases
#Microsoft #WindowsServer #Windows11 #Windows #OperatingSystems #NTLM #Kerberos #Authentication #Security #Cybersecurity #SecurityFlaws #SecurityThreats
-
https://winbuzzer.com/2026/02/02/microsoft-disable-ntlm-default-windows-kerberos-xcxwbn/
Microsoft to Disable NTLM Protocol by Default in Future Windows Releases
#Microsoft #WindowsServer #Windows11 #Windows #OperatingSystems #NTLM #Kerberos #Authentication #Security #Cybersecurity #SecurityFlaws #SecurityThreats
-
Microsoft Moves Closer to Disabling NTLM https://www.securityweek.com/microsoft-moves-closer-to-disabling-ntlm/ #Identity&Access #authentication #Windows #NTLM
-
Microsoft Moves Closer to Disabling NTLM https://www.securityweek.com/microsoft-moves-closer-to-disabling-ntlm/ #Identity&Access #authentication #Windows #NTLM
-
Fin du protocole NTLM : Microsoft dévoile son plan d’attaque en 3 phases https://www.it-connect.fr/fin-du-protocole-ntlm-microsoft-devoile-son-plan-dattaque-en-3-phases/ #ActuCybersécurité #Cybersécurité #Microsoft #Windows #NTLM
-
Fin du protocole NTLM : Microsoft dévoile son plan d’attaque en 3 phases https://www.it-connect.fr/fin-du-protocole-ntlm-microsoft-devoile-son-plan-dattaque-en-3-phases/ #ActuCybersécurité #Cybersécurité #Microsoft #Windows #NTLM
-
Microsoft anuncia que antes de finalizar este año, eliminarán el protocolo de autenticación NTLM ¿Cómo deben prepararse los administradores de TI ante este escenario?
-
#Microsoft deaktiviert das 30 Jahre alte Authentifizierungsprotokoll #NTLM in künftigen Windows-Versionen. Ab 2026 wird es standardmäßig blockiert - Kerberos übernimmt endgültig. https://winfuture.de/news,156533.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
#Microsoft deaktiviert das 30 Jahre alte Authentifizierungsprotokoll #NTLM in künftigen Windows-Versionen. Ab 2026 wird es standardmäßig blockiert - Kerberos übernimmt endgültig. https://winfuture.de/news,156533.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
#Windows :windows: -Netze: #Google :google: #Mandiant gibt Microsofts #NTLM den Todesstoß | Security https://www.heise.de/news/Windows-Netze-Google-Mandiant-gibt-Microsofts-NTLM-den-Todesstoss-11145487.html #Microsoft #GoogleMandiant
-
#Windows :windows: -Netze: #Google :google: #Mandiant gibt Microsofts #NTLM den Todesstoß | Security https://www.heise.de/news/Windows-Netze-Google-Mandiant-gibt-Microsofts-NTLM-den-Todesstoss-11145487.html #Microsoft #GoogleMandiant
-
Pourquoi votre vieux serveur Windows est une bombe à retardement, et comment la désamorcer
https://fed.brid.gy/r/https://korben.info/net-ntlmv1-danger-windows-server-rainbow-tables.html
-
Pourquoi votre vieux serveur Windows est une bombe à retardement, et comment la désamorcer
https://fed.brid.gy/r/https://korben.info/net-ntlmv1-danger-windows-server-rainbow-tables.html
-
Kerberos: атакуем трехголового пса
На сегодняшний день Active Direvtory является неотъемлемой частью функционирования любой корпоративной сети под управлением Windows. Протокол Kerberos используется в инфраструктуре Active Directory (AD) для аутентификации пользователей и сервисов. В этой статье мы поговорим о том, как работает этот протокол, и рассмотрим типовые атаки на него.
https://habr.com/ru/companies/otus/articles/967236/
#пентест #activedirectory #ntlm #Kerberos #Аутентификация #уязвимости #KDC #Атаки_на_инфраструктуру
-
Microsoft ms-photos URI NTLM Leak:
-
Microsoft ms-photos URI NTLM Leak: