Buying Internal Domain Access Again
ID: 5e796f59-534b-54dd-b5cf-b244777b77dd
STIX ID: report--5e796f59-534b-54dd-b5cf-b244777b77dd
Feed Name: TrustedSec blog
This research demonstrates that predictable WSUS/update server hostnames can be abused by registering those names in public DNS and responding to client HTTP requests with an NTLM challenge, allowing capture of NTLM hashes from Windows Update clients (including possible machine account hashes). The author documents setup, observed requests, use of Responder with multi-port listening, potential impacts (offline cracking, privilege escalation, Kerberos ticket creation), and a responsible disclosure timeline with Microsoft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
