Get a Pentest and security assessment of your IT network.

Cyber Security

New PetitPotam attack allows take over of Windows domains

A new NTLM relay attack called PetitPotam has been discovered that allows threat actors to take over a domain controller, and thus an entire Windows domain. The attack does not rely on the MS-RPRN API but instead uses the EfsRpcOpenFileRaw function of MS-EFSRPC API. The attacker would be granted a Kerberos ticket granting ticket (TGT) that would allow them to assume the identity of any device on the network.

Source: https://www.bleepingcomputer.com/news/microsoft/new-petitpotam-attack-allows-take-over-of-windows-domains/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security