7MS #526: Tales of Pentest Pwnage - Part 37

7MS #526: Tales of Pentest Pwnage - Part 37

Today's another fun tale of pentest pwnage - specifically focused on cracking a hash type I'd never paid much attention to before: cached domain credentials. I also learned that you can at least partially protect against this type of hash being captured by checking out this article, which has you set the following setting in GPO:

  • Under Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options set Interactive logon: Number of previous logons to cache to 0. Be careful, as you will have login problems if a domain controller is not immediately accessible!

In regards to defending against secretsdump, this article I found this article to be super interesting.

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
bt-dokumentar-2
forklart
stopp-verden
popradet
nokon-ma-ga
det-store-bildet
lydartikler-fra-aftenposten
aftenbla-bla
fotballpodden-2
hanna-de-heldige
frokostshowet-pa-p5
rss-ness
rss-gukild-johaug
e24-podden
dine-penger-pengeradet
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene