home.social

#ntlm — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ntlm, aggregated by home.social.

  1. Great news! go-mail v0.8.0 has just been released and it's a biggie! This release adds native NTLMv2 and DKIM support as well as bunch of cool improvements and fixes. Thanks to everybody who contributed to this release!

    github.com/wneessen/go-mail/re

    #go #gomail #smtp #dkim #ntlm
    :golang: :gopher: :gomail:

  2. Great news! go-mail v0.8.0 has just been released and it's a biggie! This release adds native NTLMv2 and DKIM support as well as bunch of cool improvements and fixes. Thanks to everybody who contributed to this release!

    github.com/wneessen/go-mail/re

    #go #gomail #smtp #dkim #ntlm
    :golang: :gopher: :gomail:

  3. Great news! go-mail v0.8.0 has just been released and it's a biggie! This release adds native NTLMv2 and DKIM support as well as bunch of cool improvements and fixes. Thanks to everybody who contributed to this release!

    github.com/wneessen/go-mail/re

    #go #gomail #smtp #dkim #ntlm
    :golang: :gopher: :gomail:

  4. It took some time, but it's finally working...

    go-mail v0.8.0 (release planned in the next few days) will add native NTMLv2 SMTP authentication support (without any 3rd party library dependency).

    I couldn't have done this without the absolute fantastic documentation of the cURL project: curl.se/rfc/ntlm.html

    Thanks @bagder for providing this. It saved me so much time!

    #go #gomail #golang #ntlm #smtp
    :golang: :gomail: :gopher:

  5. It took some time, but it's finally working...

    go-mail v0.8.0 (release planned in the next few days) will add native NTMLv2 SMTP authentication support (without any 3rd party library dependency).

    I couldn't have done this without the absolute fantastic documentation of the cURL project: curl.se/rfc/ntlm.html

    Thanks @bagder for providing this. It saved me so much time!

    #go #gomail #golang #ntlm #smtp
    :golang: :gomail: :gopher:

  6. GNU SASL 2.2.4 closes a heap-disclosure flaw (CWE-908, CVSS 6.5 as claimed) in _gsasl_ntlm_client_step: the code allocated a fixed 1,076-byte structure with malloc rather than calloc, then accepted short Type-2 challenges from the server, leaving roughly 1,060 uninitialized bytes that get echoed back in the client response. Versions 2.2.3 and earlier linked against libntlm are affected. Should NTLM still be reachable in new deployments at all?
    #security #NTLM

  7. 「NTLM」の廃止、「Kerberos」への移行は第2フェイズへ ~Microsoftが発表/「IAKerb」「LocalKDC」が今月にもCanaryチャネルでパブリックプレビュー
    forest.watch.impress.co.jp/doc

    #forest_watch_impress #Windows_11 #NTLM #Kerberos #IAKerb #LocalKDC #セキュリティ #Windows #インターネット #ネットワーク

  8. 「NTLM」の廃止、「Kerberos」への移行は第2フェイズへ ~Microsoftが発表/「IAKerb」「LocalKDC」が今月にもCanaryチャネルでパブリックプレビュー
    forest.watch.impress.co.jp/doc

    #forest_watch_impress #Windows_11 #NTLM #Kerberos #IAKerb #LocalKDC #セキュリティ #Windows #インターネット #ネットワーク

  9. 「NTLM」の廃止、「Kerberos」への移行は第2フェイズへ ~Microsoftが発表/「IAKerb」「LocalKDC」が今月にもCanaryチャネルでパブリックプレビュー
    forest.watch.impress.co.jp/doc

    #forest_watch_impress #Windows_11 #NTLM #Kerberos #IAKerb #LocalKDC #セキュリティ #Windows #インターネット #ネットワーク

  10. Responder Tool for Network Credential Capture in Active Directory

    In this article, I cover how Responder works, common credential capture techniques, and practical mitigation strategies for defending Active Directory environments.

    denizhalil.com/2026/05/18/resp

    #CyberSecurity #ActiveDirectory #Responder #LLMNR #NTLM #CredentialCapture #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #EthicalHacking #DenizHalil

  11. Responder Tool for Network Credential Capture in Active Directory

    In this article, I cover how Responder works, common credential capture techniques, and practical mitigation strategies for defending Active Directory environments.

    denizhalil.com/2026/05/18/resp

    #CyberSecurity #ActiveDirectory #Responder #LLMNR #NTLM #CredentialCapture #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #EthicalHacking #DenizHalil

  12. Responder Tool for Network Credential Capture in Active Directory

    In this article, I cover how Responder works, common credential capture techniques, and practical mitigation strategies for defending Active Directory environments.

    denizhalil.com/2026/05/18/resp

    #CyberSecurity #ActiveDirectory #Responder #LLMNR #NTLM #CredentialCapture #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #EthicalHacking #DenizHalil

  13. Включаем EPA в FreeTDS и go-mssqldb: приключение на 5 минут

    Представьте: вы теряете контроль над SCCM — одним из самых критичных инструментов управления инфраструктурой. А точкой входа становится обычное подключение к MSSQL, где он хранит свои данные. Злоумышленник перехватывает NTLM-аутентификацию и перенаправляет её на нужный сервер — так работает NTLM relay. Мы в команде Security Engineering решили не ждать эксплуатации этой уязвимости. Меня зовут Булат Гафуров, я инженер по информационной безопасности в Яндексе. В этой статье я расскажу, почему стандартного решения оказалось недостаточно и как мы добавили поддержку механизма EPA в популярные библиотеки, чтобы переключить защиту на стороне MSSQL в режим Require, не лишив Linux- и Windows-сервисы доступа к данным.

    habr.com/ru/companies/yandex/a

    #windows #security #ntlm_relay #ntlm #ntlmrelay #epa #mssql #mssqlserver #microsoft #freetds

  14. ----------------

    🔎 AI: Integrating LLMs into Offensive Security Workflows

    Summary

    This blog outlines practical integration of large language models into offensive security engagements. Authors describe improving public proof‑of‑concept Model Context Protocol (MCP) servers for BloodHound and Burp Suite to support real‑world testing, and present LLM CLI usage patterns that enable agentic execution across reconnaissance, data enrichment, attack chaining, and reporting.

    Technical specifics
    • MCP servers: Existing MCP server projects for BloodHound and Burp Suite were adapted to work in offensive engagements, enabling LLMs to fetch, query, and reason over structured data such as Active Directory graphs and proxied web traffic.
    • LLM CLI agents: Modern CLIs (examples cited include Gemini CLI, Claude Code, and OpenAI’s Codex) shift models from single‑shot responders to autonomous operators capable of chaining actions: run a tool, parse output, decide next steps, and continue until objectives are met.
    • Example capabilities: An LLM connected to an AD graph via a MCP server can rapidly enumerate privilege escalation paths that would otherwise require hours of manual review. When paired with Burp Suite MCP, LLMs can correlate requests/responses across sessions to accelerate vulnerability triage. The authors also describe an NTLM relaying Gemini extension that demonstrates chaining of attack steps.

    Operational characteristics
    • Scope of access: An LLM CLI can operate on any tool or artifact the host environment exposes—OS utilities, custom scripts, open‑source offensive tooling, and locally hosted services—then interpret outputs to guide successive actions.
    • Agentic execution model: Gemini’s agentic design emphasizes iterative, feedback‑driven workflows where the model determines subsequent commands based on intermediate results rather than relying on a single prompt.

    What was demonstrated
    • Improved MCP integrations for BloodHound and Burp Suite adapted from public proof‑of‑concept servers.
    • A proof‑of‑concept Gemini extension automating NTLM relay orchestration.
    • Use cases spanning AD privilege path identification, web traffic correlation, automated triage, and multi‑step attack choreography.

    Limitations & considerations (as presented)
    • The writeup focuses on capabilities and demonstrated integrations; implementation specifics and environmental constraints are described at a conceptual level. The examples show how LLMs can reduce manual effort and expand coverage when granted appropriate tool access.

    🔹 llm #mcp #bloodhound #burpsuite #ntlm

    🔗 Source: armadin.com/blog-posts/automat

  15. NTLM relay attacks haven't died. They evolved.

    Abusing SamrSetInformationUser in AD lets attackers set empty passwords on accounts without triggering standard password change alerts. Classic protocol weakness, new exploitation path.

    The attack surface doesn't shrink when protocols are deprecated. It shifts to adjacent trust relationships.

    #InfoSec #ActiveDirectory #CyberSecurity #NTLM

  16. NTLM relay attacks haven't died. They evolved.

    Abusing SamrSetInformationUser in AD lets attackers set empty passwords on accounts without triggering standard password change alerts. Classic protocol weakness, new exploitation path.

    The attack surface doesn't shrink when protocols are deprecated. It shifts to adjacent trust relationships.

    #InfoSec #ActiveDirectory #CyberSecurity #NTLM

  17. Problemy NTLM: drugie starcie. Wymuszenie uwierzytelnienia NTLM

    Wstęp W poprzednim artykule poświęconym NTLM, rozebraliśmy na czynniki pierwsze podstawowe pojęcia: czym jest NetNTLM a czym hash NT, jak można przeprowadzić ataki polegające na przechwyceniu challenge NetNTLM  oraz na czym polegają podatności typu relay.   Jeżeli powyższe pojęcia nie są dla Ciebie zrozumiałe, to przed przystąpieniem do dalszej lektury, koniecznie...

    #Aktualności #Teksty #ActiveDirectory #Coercion #Kerberos #Ntlm #Windows

    sekurak.pl/problemy-ntlm-drugi

  18. Problemy NTLM: drugie starcie. Wymuszenie uwierzytelnienia NTLM

    Wstęp W poprzednim artykule poświęconym NTLM, rozebraliśmy na czynniki pierwsze podstawowe pojęcia: czym jest NetNTLM a czym hash NT, jak można przeprowadzić ataki polegające na przechwyceniu challenge NetNTLM  oraz na czym polegają podatności typu relay.   Jeżeli powyższe pojęcia nie są dla Ciebie zrozumiałe, to przed przystąpieniem do dalszej lektury, koniecznie...

    #Aktualności #Teksty #ActiveDirectory #Coercion #Kerberos #Ntlm #Windows

    sekurak.pl/problemy-ntlm-drugi

  19. Podstawowe problemy bezpieczeństwa NTLM

    W świecie nowoczesnych technologii chmurowych, uwierzytelniania wieloskładnikowego i architektury Zero Trust, łatwo zapomnieć o fundamentach, na których wciąż stoi większość firmowych sieci wewnętrznych. Mowa o środowiskach Active Directory i protokołach, które pamiętają czasy Windows NT. Jednym z takich reliktów, który pozostaje jednym z najpopularniejszych wektorów ataku podczas wewnętrznych testów penetracyjnych,...

    #Aktualności #Teksty #Ntlm #Windows #Winrm

    sekurak.pl/podstawowe-problemy

  20. Podstawowe problemy bezpieczeństwa NTLM

    W świecie nowoczesnych technologii chmurowych, uwierzytelniania wieloskładnikowego i architektury Zero Trust, łatwo zapomnieć o fundamentach, na których wciąż stoi większość firmowych sieci wewnętrznych. Mowa o środowiskach Active Directory i protokołach, które pamiętają czasy Windows NT. Jednym z takich reliktów, który pozostaje jednym z najpopularniejszych wektorów ataku podczas wewnętrznych testów penetracyjnych,...

    #Aktualności #Teksty #Ntlm #Windows #Winrm

    sekurak.pl/podstawowe-problemy

  21. NTLM для хакера. Подробное описание работы и безопасности протокола

    Привет, мир! Недавно я решил пополнить свои знания протоколов NTLM'ом; и, к большому сожалению, стоящих материалов, которые бы подробно и полно описывали работу NTLM, я не нашел (есть лишь пара годных статей на английском языке, но и они, на мой взгляд, не дают нужного уровня глубины). Потому я решил написать статью, которая бы в подробностях рассказала о том, как работает данный протокол и удовлетворила даже самого душного нерда, каким автор и является))) Изучить матчасть

    habr.com/ru/articles/993934/

    #NTLM #ntlmrelay #безопасность #сетевая_безопасность #администрирование_сетей #сетевые_протоколы #аутентификация #информационная_безопасность

  22. Kerberos zastąpi NTLM w najnowszych systemach Windows. Jak się przygotować?

    Już od dawna panuje przekonanie,To już ponad 30 lat, odkąd Microsoft wprowadził protokół NTLM (New Technology LAN Manager) służący do uwierzytelniania użytkowników w systemach Windows. I choć nadal cieszy się on dużą popularnością (nawet w najnowszych wersjach systemów Windows spotkamy ten mechanizm uwierzytelnienia) to zdaje się, że jego dni zostały...

    #WBiegu #Kerberos #Microsoft #Ntlm #Windows

    sekurak.pl/kerberos-zastapi-nt

  23. Kerberos zastąpi NTLM w najnowszych systemach Windows. Jak się przygotować?

    Już od dawna panuje przekonanie,To już ponad 30 lat, odkąd Microsoft wprowadził protokół NTLM (New Technology LAN Manager) służący do uwierzytelniania użytkowników w systemach Windows. I choć nadal cieszy się on dużą popularnością (nawet w najnowszych wersjach systemów Windows spotkamy ten mechanizm uwierzytelnienia) to zdaje się, że jego dni zostały...

    #WBiegu #Kerberos #Microsoft #Ntlm #Windows

    sekurak.pl/kerberos-zastapi-nt

  24. Microsoft anuncia que antes de finalizar este año, eliminarán el protocolo de autenticación NTLM ¿Cómo deben prepararse los administradores de TI ante este escenario?

    #Windows
    #Microsoft
    #NTLM
    #Kerberos

    notasrem.com/microsoft-elimina

  25. #Microsoft deaktiviert das 30 Jahre alte Authentifizierungsprotokoll #NTLM in künftigen Windows-Versionen. Ab 2026 wird es standardmäßig blockiert - Kerberos übernimmt endgültig. winfuture.de/news,156533.html?

  26. #Microsoft deaktiviert das 30 Jahre alte Authentifizierungsprotokoll #NTLM in künftigen Windows-Versionen. Ab 2026 wird es standardmäßig blockiert - Kerberos übernimmt endgültig. winfuture.de/news,156533.html?

  27. Kerberos: атакуем трехголового пса

    На сегодняшний день Active Direvtory является неотъемлемой частью функционирования любой корпоративной сети под управлением Windows. Протокол Kerberos используется в инфраструктуре Active Directory (AD) для аутентификации пользователей и сервисов. В этой статье мы поговорим о том, как работает этот протокол, и рассмотрим типовые атаки на него.

    habr.com/ru/companies/otus/art

    #пентест #activedirectory #ntlm #Kerberos #Аутентификация #уязвимости #KDC #Атаки_на_инфраструктуру