DC・ファイルサーバー・ワークグループPCの最小構成で、NTLM受信を止めた状態からKerberosでアクセスできるかを実機で検証。イベントID 4624/4768/4769とklistで、実際にどちらの認証が使われたかを1回ずつ裏取りしています。
Entra ID参加端末やAzure Filesなど、AD非参加の主体がKerberosを使う構成が増えている今こそ整理しておきたい話です。
https://youtu.be/NbVy-F11t2M
DC・ファイルサーバー・ワークグループPCの最小構成で、NTLM受信を止めた状態からKerberosでアクセスできるかを実機で検証。イベントID 4624/4768/4769とklistで、実際にどちらの認証が使われたかを1回ずつ裏取りしています。
Entra ID参加端末やAzure Filesなど、AD非参加の主体がKerberosを使う構成が増えている今こそ整理しておきたい話です。
https://youtu.be/NbVy-F11t2M
https://www.youtube.com/watch?v=NbVy-F11t2M
#Windows #ActiveDirectory
https://www.youtube.com/watch?v=NbVy-F11t2M
#Windows #ActiveDirectory
NTLM vs Kerberos vs LDAP: ¿cuál protege mejor los datos de tu e-commerce? Comparamos cifrado, tickets y vulnerabilidades reales antes de elegir
#ntlm #kerberos #ldap #activedirectory #autenticación
NTLM vs Kerberos vs LDAP: ¿cuál protege mejor los datos de tu e-commerce? Comparamos cifrado, tickets y vulnerabilidades reales antes de elegir
#ntlm #kerberos #ldap #activedirectory #autenticación
"It extracts Windows secrets - NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit, BitLocker keys - directly from VM memory snapshots and virtual disks, on the NAS, the hypervisor.." [1]
"It extracts Windows secrets - NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit, BitLocker keys - directly from VM memory snapshots and virtual disks, on the NAS, the hypervisor.." [1]
ngl that's a pipe dream for most orgs with legacy crap.
the real problem is letting privileged accounts touch low-tier systems. if a DA's hash is on a dev laptop, you've already lost. it's about tiering, not one protocol.
ngl that's a pipe dream for most orgs with legacy crap.
the real problem is letting privileged accounts touch low-tier systems. if a DA's hash is on a dev laptop, you've already lost. it's about tiering, not one protocol.
L'outil exploite le fait qu'une négociation NTLM non authentifiée (message Type-1 NEGOTIATE) provoque en réponse un message Type-2 CHALLENGE qui divulgue…
🟡 vérification factuelle moyenne
#NTLM #ntlmscout #Cyberveille
L'outil exploite le fait qu'une négociation NTLM non authentifiée (message Type-1 NEGOTIATE) provoque en réponse un message Type-2 CHALLENGE qui divulgue…
🟡 vérification factuelle moyenne
#NTLM #ntlmscout #Cyberveille
— from @ipurple (https://x.com/ipurple/status/2101299241993855064)
— from @ipurple (https://x.com/ipurple/status/2101299241993855064)
CVE ID : CVE-2026-91926
Published : Sept. 15, 2026, 11:49 a.m. | 26 minutes ago
Description : A flaw was found in gss-ntlmssp. A memory leak...
CVE ID : CVE-2026-91926
Published : Sept. 15, 2026, 11:49 a.m. | 26 minutes ago
Description : A flaw was found in gss-ntlmssp. A memory leak...
https://techcommunity.microsoft.com/blog/Windows-ITPro-blog/retiring-ntlm-frequently-asked-questions/4550522?utm_source=bluesky&utm_medium=social&utm_campaign=newsletter
https://techcommunity.microsoft.com/blog/Windows-ITPro-blog/retiring-ntlm-frequently-asked-questions/4550522?utm_source=bluesky&utm_medium=social&utm_campaign=newsletter
「うちはActive Directoryだから関係ない」は通用しません。DCに届かない・IPアドレス直打ち・非ドメイン参加——そんな場面で今日も静かにNTLMへ落ちています。
MicrosoftのFAQ 28問を1問ずつ日本語で追いかけました。次のリリースを待たず今すぐ着手できることも 👀
#Windows #セキュリティ
https://youtu.be/0JP3hU-K7B0
「うちはActive Directoryだから関係ない」は通用しません。DCに届かない・IPアドレス直打ち・非ドメイン参加——そんな場面で今日も静かにNTLMへ落ちています。
MicrosoftのFAQ 28問を1問ずつ日本語で追いかけました。次のリリースを待たず今すぐ着手できることも 👀
#Windows #セキュリティ
https://youtu.be/0JP3hU-K7B0
📎 Ebisuda Presentations
https://presentations.ebisuda.net/decks/ntlm-retirement-faq
📎 Ebisuda Presentations
https://presentations.ebisuda.net/decks/ntlm-retirement-faq
NTLMは次期Windowsのメジャーリリースで「削除」ではなく「既定で無効」になる予定。手元のServer 2019/2022/2025やWin10/11はどう扱われ、何から壊れるのかを順に追っています。
メンバー先行公開中で、明日9/14 18:00に一般公開します。
https://youtu.be/0JP3hU-K7B0
NTLMは次期Windowsのメジャーリリースで「削除」ではなく「既定で無効」になる予定。手元のServer 2019/2022/2025やWin10/11はどう扱われ、何から壊れるのかを順に追っています。
メンバー先行公開中で、明日9/14 18:00に一般公開します。
https://youtu.be/0JP3hU-K7B0