Skip to main content

LIVE Webinar on Zerologon Vulnerability Is Going To Take Place: Technical Analysis and Detection

 11-Plus Supercomputers Hacked With Cryptominers - Security Boulevard

I'm sure most of you have now heard of a high-risk Windows server - called Zerologon - that would allow hackers to take over business networks completely.


For those of you who don't know, in short, all supported versions of Windows Server applications are at risk of a serious patent infringement that resides in the Netlogon Remote Control Protocol for Domain Controllers.


In other words, the primary vulnerability (CVE-2020-1472) can be exploited by the attacker to stop Active Directory services, and ultimately, the Windows domain without the need for authentication.

What’s worse is that the exploitation of evidence of this error was released to the public last week, and soon after that, the attackers began exploiting vulnerabilities through programs that were not included in the wild.



As explained in our compilation based on technical analysis published by Cynet's security analysts, the main problem is Microsoft's implementation of AES-CFB8, where it failed to use the unique, random salt of these Netlogon messages.


An attacker needs to send a specially designed egg string to Netlogon messages to change the domain control password stored in Active Directory.


For THN readers who are interested in learning more about this threat in detail, including technical details, mitigation, and discovery strategies, they should join the live webinar (register here) with Aviad Hasnis, CTO at Cynet.


A free security safety education webinar is scheduled for 30 September at 5:00 PM GMT, and aims to discuss wildlife exploitation to take advantage of this crisis.


In addition, the Cynet team has also released a free discovery tool that warns you of any Zerologon abuse in your area.

 

REGISTER FOR WEBINAR HERE 

Comments

Popular posts from this blog

10 WAYS TO PROMOTE AND IMPROVE YOUR WEBSITE TRAFFIC

WEBSITE MEASUREMENT   Web traffic is measured to see the popularity of websites and personal pages or sections within a website. This is an automatically generated list of all pages that appear in the Traffic Statistics web file. The hit is generated when the file is provided. The page is considered a file, but the images are also files, so a page with 5 images can generate 6 hits (5 images and even a page). Page view is generated when a visitor requests any page on the website - the visitor always generates at least one page view (main page), but can create more. Track traffic can be recorded by inserting a small HTML code on each page of the website by tracking the external applications of the website. [2] Web traffic is sometimes measured by sniffing packets and thus random samples of traffic data are obtained, providing complete information about web traffic throughout Internet usage. The following types of information are often found when monitoring web traffic: [3]  ...

Sonos sues Google for infringing 5 more non-wire A.K.A Wireless audio patents

 Sonos has filed another patent lawsuit against Google, alleging that giant search infringes five wireless patents across the Nest and Chromecast product line. The move comes on the eve of Google's hardware hardware event on September 30, with the announcement of the Chromecast and Nest smart speaker and new Pixel phones. Sonos filed its first patent lawsuit against Google in January in a California court and the International Trade Commission; The state lawsuit was suspended while the ITC reached a decision on whether to block Google products that allegedly violated market rules. The new lawsuit was filed only in a federal court in the Western District of Texas - a recent patent for a patent case - and it represents an aggressive approach from Sonos. "We think it's important to show the depth and breadth of Google's copy," said Eddie Lazarus, a law officer at Sonos. "We showed them the 100 patent charts which we said were infringing, all to no avail." G...