Black Hills Information Security 09月29日
网络攻防:密码喷射与Azure AD侦察
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

本文探讨了非可追溯密码喷射攻击方法以及如何对Azure Active Directory进行侦察,分析了云环境下认证与授权资产的安全风险。





For this podcast we cover a couple of different topics.



First, we talk about how to password spray in a non-attributable sort of way. Beau found a way to obfuscate what RDP logs record with launching password spraying attacks. This has implications for UBEA. It is… kind of cool.



Second, we cover how to do recon against Azure Active Directory. We are seeing a huge push by organizations to move to cloud AD. And what is not to love? Placing your most sensitive authentication and authorization asset directly on the Internet…What could possibly go wrong? Well, watch and find out.



Slides available here: https://blackhillsinformationsecurity.shootproof.com/gallery/8463077



Want to know when our next live webcast is? Sign up for our emails here:https://blackhillsinfosec.us15.list-manage.com/subscribe?u=e12efe2af6573cc76c90fc019&id=b7b017ed3a





















Psst If you liked this blog, we think you’d enjoy Beau’s class:




Breaching the Cloud 





Available live/virtual and on-demand!























Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

网络攻防 密码喷射 Azure AD
相关文章