Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • How to Earn Passive Crypto on CeDeFi Exchanges bitcoin news
  • The First Digital Monetary System Built on Bitcoin – Press release Bitcoin News bitcoin news
  • Glassnode Report Says Bitcoin’s 2022 Price Drop Represents a Bear Market of ‘Historic Proportions’ – Bitcoin News bitcoin news
  • Trade Republic, Crypto.com Register as Cryptocurrency Operators in Italy – Bitcoin News bitcoin news
  • Cardano Slides Below $0.50 Alarming A Danger Ahead bitcoin news
  • Experts Analyze Conti and Hive Ransomware Gangs Chats With Their Victims cyber security news
  • Singapore Considers Imposing New Restrictions on Crypto Trading – Regulation Bitcoin News bitcoin news
  • 5 Best ICO Projects in 2022 bitcoin news

New NTLM Relay Attack Lets Attackers Take Control Over Windows Domain

Posted on June 21, 2022 By root


A new kind of Windows NTLM relay attack dubbed DFSCoerce has been uncovered that leverages the Distributed File System (DFS): Namespace Management Protocol (MS-DFSNM) to seize control of a domain.

“Spooler service disabled, RPC filters installed to prevent PetitPotam and File Server VSS Agent Service not installed but you still want to relay [Domain Controller authentication to [Active Directory Certificate Services]? Don’t worry MS-DFSNM have (sic) your back,” security researcher Filip Dragovic said in a tweet.

CyberSecurity

MS-DFSNM provides a remote procedure call (RPC) interface for administering distributed file system configurations.

The NTLM (NT Lan Manager) relay attack is a well-known method that exploits the challenge-response mechanism. It allows malicious parties to sit between clients and servers and intercept and relay validated authentication requests in order to gain unauthorized access to network resources, effectively gaining an initial foothold in Active Directory environments.

The discovery of DFSCoerce follows a similar method called PetitPotam that abuses Microsoft’s Encrypting File System Remote Protocol (MS-EFSRPC) to coerce

Windows servers, including domain controllers, into authenticating with a relay under an attacker’s control, letting threat actors potentially take over an entire domain.

CyberSecurity

“By relaying an NTLM authentication request from a domain controller to the Certificate Authority Web Enrollment or the Certificate Enrollment Web Service on an AD CS system, an attacker can obtain a certificate that can be used to obtain a Ticket Granting Ticket (TGT) from the domain controller,” the CERT Coordination Center (CERT/CC) noted, detailing the attack chain.

To mitigate NTLM relay attacks, Microsoft recommends enabling protections like Extended Protection for Authentication (EPA), SMB signing, and turning off HTTP on AD CS servers.





TheHackersNews/

cyber security news

Post navigation

Previous Post: In a Bear Market, Hold Onto Your Coins & Try to Earn More Cryptos
Next Post: Today’s Metaverse Still Not Suited for Remote Work – Metaverse Bitcoin News

Related Posts

  • Italy Data Protection Authority Warns Websites Against Use of Google Analytics cyber security news
  • Unpatched GPS Tracker Bugs Could Let Attackers Disrupt Vehicles Remotely — The Hacker News cyber security news
  • CISA Urges Organizations to Patch Actively Exploited F5 BIG-IP Vulnerability cyber security news
  • New Bluetooth Hack Could Let Attackers Remotely Unlock Smart Locks and Cars cyber security news
  • New IoT RapperBot Malware Targeting Linux Servers via SSH Brute-Forcing Attack cyber security news
  • Over a Dozen Android Apps on Google Play Store Caught Dropping Banking Malware cyber security news

Archives

  • August 2022
  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • India Freezes Peter Thiel-Backed Vauld’s Crypto and Bank Assets Worth $46 Million – Regulation Bitcoin News
  • Ethereum Price Broke Past $1,800 Despite Higher Demand At Lower Levels
  • Philippines Will Stop Accepting Crypto License Applications for 3 Years, Regulator Says – Regulation Bitcoin News
  • GAIMIN’s Early Access Event Opens Its Platform and Monetization App to Gamers – Press release Bitcoin News
  • Cardano Price Sits Pretty At $0.5, Why A Breakout Is On The Horizon

Recent Comments

No comments to show.
  • BCH Higher to Start the Weekend, MATIC Hits 15-Month Low – Market Updates Bitcoin News bitcoin news
  • Crypto Market Crash Wipes Millions of Dollars From North Korea’s Kitty of Stolen Cryptocurrencies – Bitcoin News bitcoin news
  • Crypto Derivative Traders Can Access TradingView With Broker Eightcap – Sponsored Bitcoin News bitcoin news
  • Swiss VC Launches African Blockchain Early Stage Fund – Blockchain Bitcoin News bitcoin news
  • Financial Superintendence of Colombia Presents Project to Regulate Crypto Service Providers – Bitcoin News bitcoin news
  • Yuga Labs Drops Otherside Litepaper — Document Covers the ‘Foundational Principles’ of the Metaverse Platform – Bitcoin News bitcoin news
  • Ethereum Slips, What Are The Next Vital Trading Levels For The Coin? bitcoin news
  • IMF Says Central African Republic’s Bitcoin Adoption Poses Risks – Featured Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme