You're all admins, thanks to this Microsoft Exchange zero-day and exploit

Discussion in 'other security issues & news' started by guest, Jan 25, 2019.

  1. guest

    guest Guest

    You're all admins, thanks to this Microsoft Exchange zero-day and exploit
    Easily swapped hashed passwords gives Domain Admin rights via API call. Fix may land next month
    January 25, 2019
    https://www.theregister.co.uk/2019/01/25/microsoft_exchange_hashed_passwords/
     
  2. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    Oh I'm so happy I waved goodbye to M$!
     
  3. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    This is nothing a home user needs to be concerned about.
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    Microsoft Confirms Serious ‘PrivExchange’ Vulnerability
    https://threatpost.com/microsoft-confirms-serious-privexchange-vulnerability/
     
  5. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,660
    If you want to read more articles from him, go to https://dirkjanm.io/

    Some recent articles:

    “Relaying” Kerberos - Having fun with unconstrained delegation
    https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/

    The worst of both worlds: Combining NTLM Relaying and Kerberos delegation
    https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/

    Getting in the Zone: dumping Active Directory DNS using adidnsdump
    https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.