mastodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance, open to everyone, but mainly English and French speaking.

Administered by:

Server stats:

789
active users

#ntlm

1 post1 participant0 posts today

One example why to use strong #passwords for users who use file sharing over #SMB even when the file transfers are #encrypted.
If the SMB traffic is captured/eavesdropped, then the attacker can try to crack the user password.
The attacker is able to extract challenge/response values from the Session Setup and then use #passwordcracking tools such as #hashcat

If the attack is successful, the attacker will gain not only the access to the user account, but it is also possible to decrypt the captured SMB file transfers. There is lack of perfect forward secrecy in this encryption.

For more details and practical examples, see this blog post:

malwarelab.eu/posts/tryhackme-

New cheatsheets pushed🕵️‍♂️

github.com/r1cksec/cheatsheets

Including:

A nice blogpost about different ntlm relay attack scenarios🖥️

guidepointsecurity.com/blog/be

Using the Windows Security Center service, it is possible to deactivate Windows Defender by telling the service that a different antivirus program is being used :windows:

github.com/es3n1n/no-defender

A quite interesting phishing technique in which the legitimate platform Yousign is used as a communication and hosting channel🎣

agari.com/blog/active-phishing