Still Passing the Hash 15 Years Later? Using the Keys to the Kingdom to Access All your Data

Presented at Black Hat USA 2012, July 26, 2012, 10:15 a.m. (60 minutes).

Kerberos is the cornerstone of Windows domain authentication, but NTLM is still used to accomplish everyday tasks. These tasks include checking email, sharing files, browsing websites and are all accomplished through the use of a password hash. Skip and Chris will utilize several tools that have been ÒenhancedÓ to connect to Exchange, MSSQL, SharePoint and file servers using hashes instead of passwords. This demonstrates the "so what" of losing control of the domain hashes on your domain controller: all of your data can be compromised.


Presenters:

Links:

Similar Presentations: