Active Directory security: 8 (very) low hanging fruits and how to smash those attack paths

No ratings

Presented at BSidesLisbon 2018 by

Pentester or attacker often exploit the same obvious vulnerabilities in Active directory. Come learn how to exploit and mitigate them.StorylineWelcome in Noob Firm, the most insecure network ever, we have a very large Active Directory environment and we do no security at all. For now, no one ever hacked our corporate network (at least we hope) but our new CISO requires us to perform a security assessment. Your mission, should you choose to accept it, is to evaluate our security level and fix the issues. Detailed contentIn this fully hands-on workshop, we’ll guide you through 8 of the lowest hanging fruits weaknesses that we witnessed during numerous penetration tests. You’ll learn how to : * Spot passwords inside user descriptions* Find passwords on shared folders* Spray passwords over accounts* Quickly detect obsolete workstations and servers* Get free password hashes by kerberoasting* Pivot from machine to machine by reusing local credentials* Spot machines where Domain Admins are connected* Retrieve Domain Admins credentials in memoryCrackmapexec, Powerview, SharpRoast, Mimikatz will be your best friends during this workshop. Hand-on exercises will be performed on our lab environnement with more than twenty virtual machines. For each attack, we will also discuss about mitigation techniques. Living with Kodi and a hole in your networkYevgen GoncharukN/AN/AThis presentation will show how big a risk abandoned kodi extensions and plugins can be by exploiting one and showing the potential damage that could come from an attack using sinkhole data. (No innocent kodis were harmed in the process)Kodi is one of the most used media players and in large part this is due to its extensibility, the ability to install plugins and the wide range of devices it supports. However, kodi plugins are a bigger source of trouble than it appears.In this talk I will show how kodi extensions are commonly abandoned and how someone could easily exploit this to gain access to a large number of networks or to build a massive botnet.To do this, I'l briefly explain what kodi is and how it works, show how to write an exploit to execute code on any kodi installation, and show the results of sinkholing a large number of kodi extension based domains.I'l also share a few ideas on why having your Kodi behind a TOR/your 1$ VPN provided is not that fun.