Zerologon Attack Lets Hackers Take Over Enterprise Networks Within 3 Seconds

Джерело:
Slashdot

Дата публікації:
16/09/2020 06:30

Постійна адреса новини:
http://www.vsinovyny.com/7054687

Zerologon Attack Lets Hackers Take Over Enterprise Networks Within 3 Seconds

 

16/09/2020 06:30 // Slashdot

An anonymous reader writes: Researchers have developed and published a proof-of-concept exploit for a recently patched Windows vulnerability that can allow access to an organization's crown jewels -- the Active Directory domain controllers that act as an all-powerful gatekeeper for all machines connected to a network. CVE-2020-1472, as the vulnerability is tracked, carries a critical severity rating from Microsoft as well as a maximum of 10 under the Common Vulnerability Scoring System. Exploits require that an attacker already have a foothold inside a targeted network, either as an unprivileged insider or through the compromise of a connected device. However, when this condition is met, it's literally game over for the attacked company, as an attacker can hijack its entire network within three seconds by leveraging a bug in the Netlogon authentication protocol cryptography by adding zero characters in certain Netlogon authentication parameters, bypassing authentication procedures and then changing the password for the DC server itself. The technical report from Secura B.V., a Dutch security firm, is available here.

Read more of this story at Slashdot.

 

» Читати повністю

 

« Наступна новина з архіву
Вывод значений массива на консоль - Java для начинающих
  Попередня новина з архіву
Boston Dynamics CEO talks profitability and the company’s next robots
»

 

 
© 2026 www.vsinovyny.com