DEF CON 27 - Marina Simakov - Relaying Credentials Has Never Been Easier @HackersOnBoard
DEF CON 27 - Marina Simakov - Relaying Credentials Has Never Been Easier  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 2 days ago
Active Directory has always been a popular target for attackers, with a constant rise in attack tools attempting to compromise and abuse the main secrets storage of the organization. One of the weakest spots in Active Directory environments lies in the design of one of the oldest authentication protocols - NTLM, which is a constant source of newly discovered vulnerabilities. From CVE-2015-0005, to the recent LDAPS Relay vulnerability, it is clear why this protocol is one of the attackers' favorites.

Although there are offered mitigations such as server signing, protecting the entire domain from NTLM relay is virtually impossible. If it weren't bad enough already, we will present several new ways to abuse this infamous authentication protocol, including a new critical zero-day vulnerability we have discovered which enables to perform NTLM Relay and take over any machine in the domain, even with the strictest security configuration, while bypassing all of today's offered mitigations. Furthermore, we will present why the risks of this protocol are not limited to the boundaries of the on-premises environment and show another vulnerability which allows to bypass various AD-FS restrictions in order to take over cloud resources as well.
DEF CON 27 - Marina Simakov - Relaying Credentials Has Never Been EasierDEF CON 27 - Omer Gull - SELECT code execution FROM USING SQLiteDEF CON 27 - Xiaolong Bai - HackPac Hacking Pointer Authentication in iOS User SpaceDEF CON 27 - Itzik Kotler - Process Injection Techniques Gotta Catch Them AllBlack Hat USA 2018 - Deep Dive into an ICS Firewall, Looking for the Fire HoleDEF CON 27 - Can You Track Me Now? Why The Phone Companies Are Such A Privacy DisasterBlack Hat USA 2018 - How I Learned to Stop Worrying and Love the SBOMBlack Hat USA 2018 - Remotely Attacking System FirmwareBlack Hat USA 2018 - Windows Offender Reverse Engineering Windows Defenders Antivirus EmulatorDEF CON 27 - Joshua Maddux - API-Induced SSRF How Apple Pay Scattered Vulnerabilities Across the WebDEF CON 27 - The Dark Tangent - Closing CeremoniesOver-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla Cars
HackersOnBoard |

DEF CON 27 - Marina Simakov - Relaying Credentials Has Never Been Easier

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER