This talk titled "
How we Break into Domains: What every admin should know about Windows security" was given by Niels at
Hacking at Random (HAR) 2009.
Talk Abstract: It's a cliché that most networks are hard on the outside and soft and chewy on the inside, but it's true. Securing networks is hard and it shows: most domains are easy to break into. I'll describe the weaknesses in networks we abuse to gain access to most, if not all, systems on a LAN. We'll go over some of the basics, such as problems with patching and passwords, but also some more advanced recent developments, such as hijacking Windows access tokens. I will describe how state of the art techniques can be combined to take over a domain, and how to protect your domain and your company.
Speaker Bio: Niels holds a bachelor degree in Computer Science and has been experimenting with IT security for over a decade. He has worked for Fox-IT since 2005; first as a software engineer and since 2007 as a penetration tester. He has since performed dozens of penetration tests for all sorts of companies, including governments, banks and nuclear installations. When he can find the time, Niels likes to travel to Ireland or Russia. He has a personal technical blog on
blog.teusink.net.
Special thanks go out to
@agentgambell for helping us with the video upload.