NTLM Relay Is Dead, Long Live NTLM Relay
Offered By: Hack In The Box Security Conference via YouTube
Course Description
Overview
Syllabus
Intro
Speaker Bio
Abstract
What is NTLM
message (negotiation)
message (challenge)
message (authentication)
Protocols using NTLMSSP
Windows Name Resolution
SMB Reflect Attack
Hot Potato (win7)
Relay to another machine
Relay credentials to Microsoft Exchange Server
Modern Browsers
NTLMSSP over http
Intranet Zone
Internet Explorer API
What is Policy and Zone ?
Feature on WIN7 and WIN10 • write a simple program for testing
Implementation in the browser
Another attack surface in Chrome
SMB Reflection Attack Rebirth
When can Java send HTTP request?
Why Java can automatically NTLM authentication?
How to reflect the credentials to SMB?
A real-world case
How to defend against NTLM Relay?
Acknowledgement
Taught by
Hack In The Box Security Conference
Related Courses
Ethical HackingIndian Institute of Technology, Kharagpur via Swayam Investigación en Informática Forense y Ciberderecho
University of Extremadura via Miríadax MSc Cyber Security
Coventry University via FutureLearn Network Security - Introduction to Network Security
New York University (NYU) via edX Network Security - Advanced Topics
New York University (NYU) via edX