Large Social-Engineer Toolkit Update - Adds UNC Path Attacks
ID: 2401552e-1bd1-501e-ba42-2c7da20f7f91
STIX ID: report--2401552e-1bd1-501e-ba42-2c7da20f7f91
Feed Name: TrustedSec blog
Threat Score
The report details using an embedded UNC path (via SET or in phishing/web vectors) to trigger SMB authentication from a victim's machine to an attacker-controlled host, allowing Metasploit's capture/smb module to intercept NTLM challenge/response hashes which can then be cracked; the technique requires outbound TCP/445 to be permitted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
