
(Security consultant and researcher)In February 2010, we found different vulnerabilities in the Windows SMB NTLM Authentication mechanism that have been present in Windows systems for at least 17 years (from Windows NT 3.1 to Windows Server 2008). You probably haven\'t heard about these vulnerabilities, but basically the authentication mechanism used by all Windows systems to access remote resources using SMB has been flawed, allowing attackers to get read/write access to remote resources and remote code execution without credentials, using different techniques such as passive replay attacks, active collection of duplicate challenges/responses, and prediction of challenges. These vulnerabilities is also a good example of flaws that can be found in challenge-response authentication mechanisms.
This presentation will describe the vulnerability in detail, including its scope and severity, explain different techniques to exploit the flaws found and demo fully functional exploit code allowing remote code execution.
A solo días de la edición 2011 de la ekoparty, varios trainings han sido vendidos completamente, y...
El próximo 26 de Julio de 2011, tendrá lugar la jornada solidaria #1HackParaLosChicos, enterate co...
De la mano de IMMUNITY, empresa líder en el desarrollo de aplicaciones para penetration testing, tr...
Tenemos el placer de anunciar, que el Slogan votado por la gente, para representar a la ekoparty 201...
De la mano de IMMUNITY, empresa líder en el desarrollo de aplicaciones para penetration testing, tr...
diseño: GrafikaWeb