Getting the domain admin NTLM hashes out of memory on the remote machine. You have to copy the tools across to the machine where the Domain Admin is logged into. That requires access to one of the Admin shares (usually workstations don't have any other shares), and it would also involve running the tool as a local admin of that remote workstation. If all the local admin passwords are the same, then the local admin password you got from lophtcrack on your machine would be the same as the remote workstation
Cheers Ken From: James Rankin [mailto:[email protected]] Sent: Thursday, 22 October 2009 8:05 PM To: NT System Admin Issues Subject: Re: Hmmm....anyone have any thoughts on this? I was thinking along the lines of the randomization of local admin passwords....luckily we only have about fifty actual workstations, the rest are thin clients. I'm not familiar with the tools used in the attack (apart from psexec) - can anyone explain to me which part of it requires that all the local admin passwords be the same (apologies if I am missing something painfully obvious)? Cheers, 2009/10/22 Ken Schaefer <[email protected]<mailto:[email protected]>> * Secure physical access * Don't allow people to boot alternate OSes * Do your workstations need to have $ shares enabled? Or available (e.g. block with firewall/router) *if* these are admin workstations * Randomize local Administrator passwords * Do not login locally to workstations with Domain Admin credentials. Login with normal credentials. Use other tools (e.g. RDP) with admin credentials to secured jump box or servers * Etc, etc Cheers Ken From: James Rankin [mailto:[email protected]<mailto:[email protected]>] Sent: Thursday, 22 October 2009 7:56 PM To: NT System Admin Issues Subject: Hmmm....anyone have any thoughts on this? http://securitytube.net/How-to-own-a-Windows-Domain-video.aspx Or mitigating against it, specifically....although I am not sure how effective an attack this is. I would think blocking USB access and maintaining application whitelists would be my personal first step ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
