logo

Attacking Self-Hosted Skype for Business/Microsoft Lync Installations

ID: 60252dd2-e99d-5d38-ba87-282a69ba4426

STIX ID: report--60252dd2-e99d-5d38-ba87-282a69ba4426

Feed Name: TrustedSec blog

Threat Score
72/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

**Executive summary:** This blog post provides a step-by-step offensive guide for attacking self-hosted Skype for Business (Lync) servers: locating Front-End servers via lyncdiscover subdomains, extracting internal NetBIOS/DNS information through NTLM-protected endpoints, performing timing-based user enumeration with a tool (lyncsmash), and conducting brute-force attacks against NTLM-protected directories or the WebTicket authentication service using Medusa or Burp Intruder, potentially exposing internal AD accounts and enabling access to the internal network.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.