HomeSecurityHackers exploit "Forced Authentication" for NTLM theft

Hackers exploit “Forced Authentication” for NTLM theft

Hackers exploit "forced authentication" to steal Windows NTLM.

Hackers NTLM

Cybersecurity researchers have discovered a case of “forced authentication,” exploiting a legitimate feature in a database management system that allows users to connect to external data sources. The goal of the attack is to leak a Windows user’s NT LAN Manager (NTLM) credentials , with the victim opening a specially crafted Microsoft Access file.

See more: North Korean hackers combine macOS malware tactics to evade detection

The attack begins when the victim opens an .accdb or .mdb file, with the hacker embedding a remote SQL Server database link into an MS Word document, using the Object Linking and Embedding (OLE) mechanism . The hackers' attack is dangerous, as it can leak NTLM hashes to a hacker-controlled server, thus bypassing traditional detection methods.

If the victim opens the file and clicks on the linked table, the victim server contacts the server controlled by the hacker. A relay attack is then performed, entering an authentication process with a selected server . Microsoft and 0patch have developed workarounds for the issue that occurs in various versions of Office/Access.

The development continues, as Microsoft announced its plans to replace NTLM with Kerberos in Windows 11 for increased security.

Hackers NTLM

Read more: Hacking Attack or Student Prank in Lee County Schools?

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS