DEF CON 31 - A Broken Marriage Abusing Mixed Vendor Kerberos Stacks - Ceri Coburn

Поділитися
Вставка
  • Опубліковано 15 вер 2023
  • The Windows Active Directory authority and the MIT/Heimdal Kerberos stacks found on Linux/Unix based hosts often coexist in harmony within the same Kerberos realm. This talk and tool demonstration will show how this marriage is a match made in hell. Microsoft's Kerberos stack relies on non standard data to identify it's users. MIT/Heimdal Kerberos stacks do not support this non standard way of identifying users. We will look at how Active Directory configuration weaknesses can be abused to escalate privileges on *inux based hosts joined to the same Active Directory authority. This will also introduce an updated version of Rubeus to take advantage of some of these weaknesses.
  • Наука та технологія

КОМЕНТАРІ • 12

  • @bnk28zfp
    @bnk28zfp 9 місяців тому +2

    amazing!!! thank you!!!😮

  • @theflowpowa42oshow
    @theflowpowa42oshow Місяць тому

    I'm the best Monito! Ya heard?

  • @iwuvu5940
    @iwuvu5940 3 місяці тому

    Alway good to listen to defcon

  • @geroffmilan3328
    @geroffmilan3328 9 місяців тому

    *Very* interesting, good work.

  • @Coaden0000
    @Coaden0000 Місяць тому

    Are you my son one of my kids. I believe you just might fit the boxes except maybe 1 or a few at most lol

  • @divtest
    @divtest 8 місяців тому

    cool

  • @crystaldemons207
    @crystaldemons207 4 місяці тому

    If it sees itself self recognized as it own entity it already breached the wall..

  • @crystaldemons207
    @crystaldemons207 4 місяці тому

    Enterprise is a self recognized term.

  • @crystaldemons207
    @crystaldemons207 4 місяці тому

    Corporate coupons.

  • @crystaldemons207
    @crystaldemons207 4 місяці тому

    Vpn breach

  • @benkasumpa6246
    @benkasumpa6246 4 місяці тому

    May I please get your email sir ,I got many questions