Getting Credentials from a locked Windows PC in 12 Seconds Joe - - PowerPoint PPT Presentation

getting credentials from a locked windows pc in 12 seconds
SMART_READER_LITE
LIVE PREVIEW

Getting Credentials from a locked Windows PC in 12 Seconds Joe - - PowerPoint PPT Presentation

Getting Credentials from a locked Windows PC in 12 Seconds Joe Granneman, MBA, CISSP Principal Consultant About illumination.io Rockford based Cybersecurity Services Penetration Testing HIPAA, PCI, and GLBA Compliance Testing


slide-1
SLIDE 1

Getting Credentials from a locked Windows PC in 12 Seconds

Joe Granneman, MBA, CISSP – Principal Consultant

slide-2
SLIDE 2

About illumination.io

  • Rockford based Cybersecurity Services

– Penetration Testing – HIPAA, PCI, and GLBA Compliance Testing – Social Engineering Testing – Incident Response – Disaster Recovery Planning – Security Architecture Design – Strategic Information Security Planning – Information Security Program Development

slide-3
SLIDE 3

About the Speaker

slide-4
SLIDE 4

Your Mission

slide-5
SLIDE 5

Your Tools

slide-6
SLIDE 6

You Only Need 12 Seconds

slide-7
SLIDE 7

So how does this work?

slide-8
SLIDE 8

Windows Authentication is a Mess of Old Technology

NTLMv1 NTLMv2

slide-9
SLIDE 9

What is a LAN Turtle?

slide-10
SLIDE 10

The Secret Sauce

slide-11
SLIDE 11

LAN Turtle in Action

slide-12
SLIDE 12

What did we get?

  • Proxy-Auth-NTLMv2-172.16.84.113.txt
  • Bob::LAPTOP-

GK7EEVOS:1122334455667788:1A6B63055DA390F158E33C470F318 E76:0101000000000000AFD31FB3F133D2014423BC942F310F9C00 0000000200060053004D0042000100160053004D0042002D00540 04F004F004C004B00490054000400120073006D0062002E006C00 6F00630061006C0003002800730065007200760065007200320030 00300033002E0073006D0062002E006C006F00630061006C00050 0120073006D0062002E006C006F00630061006C00080030003000 0000000000000000000000200000ADA2DDBB95B9C6DDDF83211E AC531214D6B257A2FBB5AA90AD99C06E26F168F10A00100000000 00000000000000000000000000009001A0048005400540050002F 00700072006F00780079007300720076000000000000000000

slide-13
SLIDE 13

Encryption Methods Matter

  • NetNTLMv1 : 27362.0 MH/s
  • NetNTLMv2 : 2115.9 MH/s
  • NTLM : 64790.0 MH/s
  • LANMAN : Instant
slide-14
SLIDE 14

GPU Cracking Engaged

slide-15
SLIDE 15

How to Defend?

slide-16
SLIDE 16

How to Defend?

Disable NETBIOS over TCP/IP in DHCP Manager

slide-17
SLIDE 17

How to Defend?

Disable NetBIOS over TCP/IP in NIC Settings

slide-18
SLIDE 18

Don’t Forget the Basics

  • Strong passwords still work

– 12 characters is the new minimum

  • Utilize dual factor auth where possible
  • Physical security is still king
slide-19
SLIDE 19

Getting Credentials from a locked Windows PC in 12 Seconds

Joe Granneman, MBA, CISSP – Principal Consultant