default Stage Background

Log4J and NoPac - From external attacker to Domain-Admin in 10 minutes

Two fatal vulnerabilities that together allowed attackers to take over entire corporate networks in near to no time.

Topic

Awareness / Phishing / FraudEndpoint ProtectionIdentity and access managementTrend topic

When & Where

calendar_month

Wed, 03/16/2022, 09:45 - 10:15

Download session as iCaldownload_for_offline

Details

  • Format:

    it-sa insights

Session description


Most people have certainly already heard about Log4J. However, the coverage of the Active Directory vulnerability called NoPac was not strong, although the impact was comparably far-reaching. This talk will demonstrate how two vulnerabilities were enough for attackers and ransomware groups to become domain administrators and take over entire corporate networks in under 10 minutes. The technical aspects behind the vulnerabilities will be discussed and then a live demo will show how easy it is for attackers to exploit these vulnerabilities.

Speaker

Moderator