BlueHat IL 2023 - James Forshaw - Windows Authentication

  Рет қаралды 3,167

Microsoft Israel R&D Center

Жыл бұрын

Hunting for Bugs in the Legacy Windows Authentication Stack
Authentication is crucial to Windows security, especially in enterprise environments. While there's a push to move towards web-based authentication such as OAuth, many of the legacy authentication protocols, among them NTLM and Kerberos, are still in use today. These protocols stretch back over 20 years; with code and design choices baked in for so long, it's an interesting area to look for high-impact security issues.
This presentation will go through the work I've done in the past two years to hunt for bugs in the legacy Windows authentication stack. I'll share my overall methodology for the hunt, tooling that I've developed to aid in the research and highlight some intriguing vulnerabilities that I discovered. Some of these vulnerabilities are down to design choices made 20 years ago, others are in brand new code and range from privilege escalation, authentication bypass and remote code execution.

Пікірлер
Хотите поиграть в такую?😄
00:16
МЯТНАЯ ФАНТА
Рет қаралды 3,4 МЛН
孩子多的烦恼?#火影忍者 #家庭 #佐助
00:31
火影忍者一家
Рет қаралды 52 МЛН
Klavye İle Trafik Işığını Yönetmek #shorts
0:18
Osman Kabadayı
Рет қаралды 5 МЛН
Как удвоить напряжение? #электроника #умножитель
1:00
Hi Dev! – Электроника
Рет қаралды 861 М.
Battery  low 🔋 🪫
0:10
dednahype
Рет қаралды 11 МЛН