Crypto Ticker:
sysadmin from Cyber Security News

How DCSync Attack Helps Hackers Steal Password Hashes Silently from Active Directory

Guru Baran
5 hours ago
5 Views
0 Comments
How DCSync Attack Helps Hackers Steal Password Hashes Silently from Active Directory

Active Directory is the beating heart of identity in most enterprises, and its single most valuable secret is the password hash of every user, service, and machine account. A DCSync attack lets an adversary walk out with those hashes without ever logging into a domain controller, dropping a tool on it, or reading the NTDS.dit database off disk. Instead, the attacker simply asks a domain controller to hand the secrets over, using the very same replication protocol that domain controllers use to synchronize with one another. Technically, DCSync impersonates a domain controller and issues a directory-replication request over the Microsoft Directory Replication Service Remote Protocol (MS-DRSR). The stages of a DCSync attack, from...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!