WPAD Man in the Middle (Clear Text Passwords)
ID: 231ee0b8-f3db-5cbb-8e6a-b5459f7d98a5
STIX ID: report--231ee0b8-f3db-5cbb-8e6a-b5459f7d98a5
Feed Name: TrustedSec blog
This blog-style tutorial describes a practical credential-harvesting technique that abuses Internet Explorer's "Automatically detect proxy settings" behavior and name resolution fallbacks (DNS/WINS/LLMNR) to serve a malicious wpad.dat and capture clear-text HTTP basic-auth credentials using the Responder tool; the post includes installation and usage examples, captured credential output, and remediation advice (add a WPAD DNS entry or disable autodetect proxy settings via Group Policy).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
