Jun 30, 2022

Remediate Security Recommendations with Governance


This webinar introduces the new Governance feature in Defender for Cloud. It helps to drive security posture improvement by creating governance rules, notify owners and monitor it, and take action to improve secure score.

 

Building an automated process

To make sure your organization is systematically improving its security posture, you can define rules that assign an owner and set the due date for resources in the specified recommendations. That way resource owners have a clear set of tasks and deadlines for remediating recommendations.

  • Defining governance rules to automatically set the owner and due date of recommendations
  • Manually assigning owners and due dates for recommendation remediation
  • Tracking the status of the recommendations for further action
  • Tracking progress by rule with the governance report
  • Weekly email notifications to the owners and managers.

 

Links:

Jun 24, 2022

Using winget

A quick note on learning how to use winget.exe cmdline.


Install Packages

PS> winget install python


Search for Packages

PS> winget search mysql


Show Package Details

PS> winget show Notepad++


Manage Sources (List, Add, Update, Remove, Reset)

PS> winget source list

PS> winget source add --name azure https://winget.azureedge.net/cache

PS> winget source update

PS> winget source remove --name azure

PS> winget source reset --force


List Packages

PS> winget list


Uninstall Packages

PS> winget uninstall Notepad++.Notepad++


Links:

Jun 23, 2022

Windows Cmdline

A series of blog posts from Windows Command-Line.

  1. Backgrounder
  2. The Evolution of the Windows Command-Line
  3. Inside the Windows Console
  4. Introducing the Windows Pseudo Console (ConPTY)
  5. Unicode and UTF-8 Output Text Buffer

Try to follow the text encoding history from 7-bit ASCII text encoding, to 8-bit, and UTF-8 encoding; all the way to command-line, shells, and consoles.

Jun 22, 2022

New Attack Vector PetitPotam

Still remember PetitPotam attack?

PetitPotam is an NTLM Relay Attack tracked as CVE-2021-36942 that French security researcher GILLES Lionel discovered, aka Topotam, in July 2021. 

It is an NTLM Relay attack that allows threat actors to force devices, even domain controllers, to authenticate against malicious servers they control. Once a device authenticates, the malicious server can impersonate the device and gain all of its privileges.

The PetitPotam attack allowed unauthenticated users to use the EfsRpcOpenFileRaw function of the MS-EFSRPC API to force a device to perform NTLM authentication against attacker-controlled servers.

In 2022 (Jan ~ Mar), a security researcher, Raphael John, says that he discovered that PetitPotam was still working when conducting pentests. However, when he disclosed it to Microsoft, they fixed it under a new CVE rather than the original one assigned to PetitPotam.

A PoC tool, from Topotam, to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw. 

The tool uses the LSARPC named pipe with inteface c681d488-d850-11d0-8c52-00c04fd90f7e because it's more prevalent. But it's possible to trigger with the EFSRPC named pipe and interface df1941c5-fe89-4e79-bf10-463657acf44d. It doesn't need credentials against Domain Controller. And disabling the EFS service seems not to mitigate the "feature".

 

During the May 2022 Patch Tuesday, Microsoft released a security update for an actively exploited NTLM Relay Attack labeled as a 'Windows LSA Spoofing Vulnerability' and tracked as CVE-2022-26925.

In June 2022, a new DFSCoerce Windows NTLM relay attack has been discovered that uses MS-DFSNM, Microsoft's Distributed File System, to completely take over a Windows domain.

A security researcher, Filip Dragovic, released a proof-of-concept script for a new NTLM relay attack called 'DFSCoerce' that uses Microsoft's Distributed File System (MS-DFSNM) protocol to relay authentication against an arbitrary server.

The DFSCoerce script is based on the PetitPotam exploit, but instead of using MS-EFSRPC, it uses MS-DFSNM, a protocol that allows the Windows Distributed File System (DFS) to be managed over an RPC interface.

To coerce a remote server to authenticate against a malicious NTLM relay, threat actors could use various methods, including the MS-RPRN, MS-EFSRPC (PetitPotam), and MS-FSRVP protocols.

These mitigations include disabling NTLM on domain controllers, disabling web services on Active Directory Certificate Services servers, and enabling Extended Protection for Authentication and signing features, such as SMB signing, to protect Windows credentials.


Links:

Jun 21, 2022

Code Bloat

The golden age of programming used to be when CPUs and memory were limited; now, we live in a pile of inefficient rubbish.