CQURE Hacks #68: NTLM Relay Attacks Explained and Why It’s Time to Phase Out NTLM
We begin on the Domain Controller, where the Group Policy setting “Network security: Restrict NTLM: NTLM authentication in this domain” is initially set to Disabled. This allows NTLM-based authentication to proceed – opening the door for potential relay attacks. On the attacker machine (running Kali Linux), the Responder and Impacket’s ntlmrelayx tools are launched. Once … Continue reading CQURE Hacks #68: NTLM Relay Attacks Explained and Why It’s Time to Phase Out NTLM
Copy and paste this URL into your WordPress site to embed
Copy and paste this code into your site to embed