Getting the domain admin NTLM hashes out of memory on the remote machine.

You have to copy the tools across to the machine where the Domain Admin is 
logged into. That requires access to one of the Admin shares (usually 
workstations don't have any other shares), and it would also involve running 
the tool as a local admin of that remote workstation. If all the local admin 
passwords are the same, then the local admin password you got from lophtcrack 
on your machine would be the same as the remote workstation

Cheers
Ken

From: James Rankin [mailto:[email protected]]
Sent: Thursday, 22 October 2009 8:05 PM
To: NT System Admin Issues
Subject: Re: Hmmm....anyone have any thoughts on this?

I was thinking along the lines of the randomization of local admin 
passwords....luckily we only have about fifty actual workstations, the rest are 
thin clients. I'm not familiar with the tools used in the attack (apart from 
psexec) - can anyone explain to me which part of it requires that all the local 
admin passwords be the same (apologies if I am missing something painfully 
obvious)?

Cheers,
2009/10/22 Ken Schaefer <[email protected]<mailto:[email protected]>>

*         Secure physical access

*         Don't allow people to boot alternate OSes

*         Do your workstations need to have $ shares enabled? Or available 
(e.g. block with firewall/router) *if* these are admin workstations

*         Randomize local Administrator passwords

*         Do not login locally to workstations with Domain Admin credentials. 
Login with normal credentials. Use other tools (e.g. RDP) with admin 
credentials to secured jump box or servers

*         Etc, etc

Cheers
Ken


From: James Rankin [mailto:[email protected]<mailto:[email protected]>]
Sent: Thursday, 22 October 2009 7:56 PM
To: NT System Admin Issues
Subject: Hmmm....anyone have any thoughts on this?

http://securitytube.net/How-to-own-a-Windows-Domain-video.aspx

Or mitigating against it, specifically....although I am not sure how effective 
an attack this is. I would think blocking USB access and maintaining 
application whitelists would be my personal first step





~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to