HomeSecurityActive Directory is a favorite target of hackers. But why?

Active Directory is a favorite target for hackers. But why?

Security experts have reported on the risks faced by Active Directory. The service, which is built into most Windows Server operating systems, is the main way to manage Windows domain networks. However, this also hides the risk of being exploited by hackers

According to many information security professionals, Active Directory is the primary identity platform for many businesses around the world. It is used to connect different systems together and has therefore become a prime target for hackers. This is because if someone who intends to attack manages to get into Active Directory, then they could potentially have access to all the systems connected to that network.

Active Directory

A digital forensic investigation conducted by security firm Bitdefender has identified a cybercrime known as Carbanak, which has a malware called Cobalt Strike Beacon. Bitdefender said the malware has the ability to execute commands on systems, record keystrokes, take screenshots and even deploy memory manipulation tools such as Mimikatz or multiple Active Directory hosts. All of the above can help would-be hackers gain access to other systems.

Rapid7 released a report titled Under the Hoodie 2019. It summarized 180 penetration tests over a nine-month period. 40% of the tests focused on identifying vulnerabilities and exposing the organization to internet risks. 36%, on the other hand, focused on internal network assessments. According to the research, every business has at least one vulnerability that a hacker can exploit.

Of the vulnerabilities found during internal testing, Rapid7 said 11% contained credentials found in memory, which could potentially allow a hacker to access other systems. Meanwhile, 9% of all internal vulnerabilities involve Kerberosting.

Active Directory

Kerberosting is a term coined by Tim Medin. It is essentially a privilege escalation technique that has proven to be very effective in extracting service account credentials across a domain.

Many organizations use accounts with weak passwords, which have never expired and usually enjoy excessive privileges.

Last June, the department's inspector general said that inadequate management of Active Directory put the United States Patent and Trademark Office at risk.

Rapid7 tester Nick Powers, in the company's report, was looking for wireless and internal network vulnerabilities in a system of eight hospitals. The wireless network there seemed very well locked down. But the network had many non-standard devices, most of which were medical. Some were running outdated versions of Windows. One of them had accessed a user in the Active Directory service, which allowed the recovery of that user's credentials from memory.

Experts argue that there are specific defenses that should be created and operated in organizations to avoid such problems.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS