Exploring SCCM by Unobfuscating Network Access Accounts
ID: b9883521-6c76-5b09-a574-9361f3f85308
STIX ID: report--b9883521-6c76-5b09-a574-9361f3f85308
Feed Name: XPN Infosec Blog
This blog post reverse-engineers SCCM's HTTP API and client registration to show a practical abuse path: an attacker able to create a computer account can register a fake SCCM client, cause it to be Approved, download secret NAAConfig policies encrypted to the client's key, and recover Network Access Account credentials offline by decrypting the PKCS#7 payload and applying the client-side unobfuscation routine; the author provides analysis, debugging notes, and proof-of-concept code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
