light bulb

Did You Know?



Reply
Highlighted
Posts: 10,584
Topics: 7,207
Kudos: 17,679
Registered: ‎06-12-2013

Critical design flaw in Active Directory could allow for a password change

Microsoft contends the general issue has been long-known, but Israel-based Aorato has developed a working attack

By Jeremy Kirk

 

Microsoft's widely used software for brokering network access has a critical design flaw, an Israeli security firm said, but Microsoft contends the issue has been long-known and defenses are in place.

Aorato used public information to craft a proof-of-concept attack that shows how an attacker can change a person's network password, potentially allowing access to other sensitive systems, said Tal Be'ery, its vice president of research.

"The dire consequences we are discussing -- that an attacker can change the password -- was definitely not known," said Be'ery in a phone interview Tuesday.

About 95 percent of Fortune 500 companies use Active Directory, making the problem "highly sensitive," Aorato wrote on its blog.

The company's research focuses on NTLM, an authentication protocol that Microsoft has been trying to phase out for years. All Windows versions older than Windows XP SP3 used NTLM as a default, and newer Windows versions are compatible with it in combination with its successor, Kerberos.

 

Full Article

Community Expert Advisor

Posts: 11,289
Topics: 799
Kudos: 12,098
Ideas: 6
Registered: ‎02-03-2012

Re: Critical design flaw in Active Directory could allow for a password change

[ Edited ]

Thanks Jeff I was just reading that article via a MVP channel so looks like another big patch needs to come out at some point. Also from PCWorld: http://www.pcworld.com/article/2454103/critical-design-flaw-in-active-directory-could-allow-for-a-pa...

 

Daniel Smiley Wink

coollogo_com-133794099.gif


asapvip.pngSigGVIP.pngEPA.gif


Webroot® SecureAnywhere™ Internet Security Complete Beta Tester v9.0.9.77 on my main system Alienware 17R2 with Windows 10 Enterprise x64 Version 1511 (Build 10586.318) & HTC One M8 Android 6.0 Marshmallow with WSA Mobile Complete v3.7.1.7660 which is full Cloud now as well!


MVP.gif.pngMicrosoft® MVP Consumer Security 2012/17


Twitter1.png  Untitled-1.png  ambassadorsig.png