Dissecting NTLM EPA & building a MitM proxy
Key | Action |
---|---|
K or space | Play / Pause |
M | Mute / Unmute |
C | Select next subtitles |
A | Select next audio track |
V | Show slide in full page or toggle automatic source change |
left arrow | Seek 5s backward |
right arrow | Seek 5s forward |
shift + left arrow or J | Seek 10s backward |
shift + right arrow or L | Seek 10s forward |
control + left arrow | Seek 60s backward |
control + right arrow | Seek 60s forward |
shift + down arrow | Decrease volume |
shift + up arrow | Increase volume |
shift + comma | Decrease playback rate |
shift + dot or shift + semicolon | Increase playback rate |
end | Seek to end |
beginning | Seek to beginning |
Share this media
HLS video stream
You can use an external player to play this stream (like VLC).
HLS video streamWhen subscribed to notifications, an email will be sent to you for all added annotations.
Your user account has no email address.
Information on this media
Links:
Number of views:
43Creation date:
July 6, 2022Speakers:
Hugo VincentLicense:
CC BY-SA v4Description
Have you ever come across a website that used NTLM-based authentication, and you just could not authenticate with your browser nor BurpSuite even though you knew your credentials were correct? NTLM Extended Protection for Authentication (EPA) might be the culprit... Indeed, Firefox, among others, does not support the NTLM EPA mechanism and fails to authenticate.
This new protection was implemented to prevent relay attacks on webservers. With the rise of the powerful attack chain that involves ADCS, Petit Potam and NTLM relay, this protection has proven to be very useful!
What can we do then?! How are we going to use all our favorite tools? By creating a proxy of course! This implied multiple problematics, such as TLS interception, HTTP parsing, NTLM authentication, EPA implementation, and so on.
Security Ninja @ Synacktiv
Other media in the channel "2022"
- 19 views, 5 this yearClosingJuly 6th, 2022
- 46 views, 9 this yearkdigger: A Context Discovery Tool for Kubernetes Penetration TestingJuly 6th, 2022
- 66 views, 18 this year, 4 this monthFinding Java deserialization gadgets with CodeQLJuly 6th, 2022
- 80 views, 12 this yearMobSF for penetration testersJuly 6th, 2022
- 76 views, 11 this yearImprove your Malware Recipes with CyberchefJuly 6th, 2022
- 347 views, 167 this year, 5 this monthTAPIR : Trustable Artifact Parser for Incident ResponseJuly 6th, 2022