
Log4J and NoPac - From external attacker to Domain-Admin in 10 minutes
Two fatal vulnerabilities that together allowed attackers to take over entire corporate networks in near to no time.
Topic
Awareness / Phishing / FraudEndpoint ProtectionIdentity and access managementTrend topic
When & Where
Wed, 03/16/2022, 09:45 - 10:15
Details
Format:
it-sa insights
Session description
Most people have certainly already heard about Log4J. However, the coverage of the Active Directory vulnerability called NoPac was not strong, although the impact was comparably far-reaching. This talk will demonstrate how two vulnerabilities were enough for attackers and ransomware groups to become domain administrators and take over entire corporate networks in under 10 minutes. The technical aspects behind the vulnerabilities will be discussed and then a live demo will show how easy it is for attackers to exploit these vulnerabilities.
Speaker
Moderator
