logo

Buying Internal Domain Access Again

ID: 5e796f59-534b-54dd-b5cf-b244777b77dd

STIX ID: report--5e796f59-534b-54dd-b5cf-b244777b77dd

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This research demonstrates that predictable WSUS/update server hostnames can be abused by registering those names in public DNS and responding to client HTTP requests with an NTLM challenge, allowing capture of NTLM hashes from Windows Update clients (including possible machine account hashes). The author documents setup, observed requests, use of Responder with multi-port listening, potential impacts (offline cracking, privilege escalation, Kerberos ticket creation), and a responsible disclosure timeline with Microsoft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.