Phishing The Resistant: Phishing For Primary Refresh Tokens In Microsoft Entra - Dirk-Jan Mollema

  Рет қаралды 2,117

DEFCON Switzerland

DEFCON Switzerland

15 күн бұрын

Dirk-Jan Mollema (Outsider Security)
Microsoft Entra ID (formerly Azure AD) offers many options to harden your tenant against attackers.
Most of these options are enforced using Conditional Access policies, which for example allow you to restrict users to authenticate with only phishing resistant MFA methods such as Yubikeys and Windows Hello for Business. These MFA methods are resistant against common attacks, such as attacker-in-the-middle attacks via fake login pages, because they will only authenticate against the real Microsoft websites. There is however a catch: the provisioning of such MFA methods is often done from scenarios where such strong authentication cannot be enforced, such as during the device setup. In this talk we will see that by phishing for regular refresh tokens, using some tricks that Microsoft uses during the Windows installation, we can actually obtain a Primary Refresh Token and even provision these Phishing Resistant authentication methods by ourselves. The talk will also cover new mitigations that Microsoft introduced to combat these attacks, and what you can do to protect your tenant.

Пікірлер: 1
@kalidsherefuddin
@kalidsherefuddin 12 күн бұрын
Thanks
Configure Windows Hello for Business for Passwordless Authentication
8:49
Microsoft Security
Рет қаралды 2,4 М.
3M❤️ #thankyou #shorts
00:16
ウエスP -Mr Uekusa- Wes-P
Рет қаралды 15 МЛН
Happy 4th of July 😂
00:12
Pink Shirt Girl
Рет қаралды 62 МЛН
Azure AD Certificate-Based Authentication
24:55
John Savill's Technical Training
Рет қаралды 29 М.
Whats new in Microsoft 365 | June Updates
19:07
T-Minus365
Рет қаралды 14 М.
FIDO Promises a Life Without Passwords
9:58
IBM Technology
Рет қаралды 397 М.
Lock Down Your Microsoft 365: Your Essential Security Policies
22:09
Jonathan Edwards
Рет қаралды 32 М.
Stop Microsoft from getting your data!
11:45
Liron Segev
Рет қаралды 112 М.
AZ-305 Designing Microsoft Azure Infrastructure Solutions Study Cram - Over 100,000 views
3:38:35
John Savill's Technical Training
Рет қаралды 425 М.
Собери ПК и Получи 10,000₽
1:00
build monsters
Рет қаралды 2,7 МЛН
Хотела заскамить на Айфон!😱📱(@gertieinar)
0:21
Взрывная История
Рет қаралды 6 МЛН