Posts

Showing posts with the label Windows Security

Windows Remote Execution: The Techniques Attackers Use to Move Laterally

Lateral movement in a Windows environment rarely involves an exploit. An attacker with valid credentials uses the same remote execution mechanisms administrators use, which is why it looks like legitimate activity and why detection has to be based on pattern rather than on the mechanism itself. How the credentials are obtained is covered under pass-the-hash ; this is what is done with them. Service creation The oldest and most reliable. Connect to the target's administrative share, copy an executable, create a service pointing at it remotely, start the service, then delete it afterwards. The service runs as SYSTEM. It is noisy by modern standards, and it still works everywhere, which is why it remains common. The detection is straightforward: event 7045 records a service installation, and a service created remotely with a random or short name, running from a temporary path, and removed minutes later is not an administrator doing maintenance. WMI Windows Management Instrume...

NTLM Explained: Pass-the-Hash, Relay, and Why It Is Being Retired

NTLM is the authentication protocol Windows used before Kerberos and still falls back to constantly. Its two fundamental weaknesses — the password hash functions as the credential, and the authentication is not bound to a service — are the reason two of the most durable Windows attacks exist. This article is about the protocol itself; how attackers get clients to authenticate to them in the first place is covered under LLMNR and NBT-NS poisoning . The challenge-response exchange A client requests access. The server sends a random challenge. The client computes a response using the challenge and its NT hash — a hash derived from the password — and returns it. The server, or a domain controller on its behalf, computes the same value and compares. The password itself never crosses the network, which was the design goal. What matters is what follows from the details. NTLMv1 uses a weak construction that can be broken to recover the hash outright and should be d...

Windows Privilege Escalation: The Misconfigurations That Get Exploited

An attacker who lands on a Windows host almost never arrives as an administrator. Privilege escalation is how they get there, and the overwhelming majority of real escalations exploit configuration rather than a kernel vulnerability. That is good news for defenders, because configuration is auditable. Service misconfigurations Unquoted service paths. A service whose executable path contains spaces and is not enclosed in quotes causes Windows to try each space-delimited prefix in turn, appending .exe . A path such as C:\Program Files\My App\service.exe makes Windows try C:\Program.exe first. If a low-privileged user can write to one of those locations, they place a file there and it runs with the service's privileges at next start. Weak service permissions. If a standard user can modify a service's configuration, they can point its binary path at anything and restart it. The service runs as SYSTEM, so the escalation is immediate and requires no exploit at all. Weak file...

LLMNR and NBT-NS Poisoning: How Responder Harvests Windows Credentials

Responder is the reference tool for one of the most reliable attacks on an internal Windows network. It does not exploit a vulnerability in the usual sense. It exploits a fallback behavior that Windows performs by default , and it works on networks that are otherwise well patched. Understanding it teaches you more about name resolution and authentication than almost any other single technique. The fallback that creates the opening When a Windows host needs to resolve a name, it tries DNS first. If DNS returns no answer — a typo in a share path, a decommissioned server still in a login script, a mapped drive to a host that no longer exists — Windows does not give up. It falls back to Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS), broadcasting to the local segment: does anyone here answer to this name? That broadcast is unauthenticated. Any host on the segment may answer, and the first answer wins. An attacker running Responder simply answe...

Process Injection: How Code Ends Up Running Inside Something Legitimate

Process injection makes code run inside a process that already exists. The malicious code inherits that process's identity, its privileges, and its reputation — so network connections appear to come from a signed, trusted application, and a scanner looking for suspicious files finds nothing because the code was never a file on disk. Why attackers do it Three benefits, and they compound. Evasion. Application allowlisting permits the legitimate process, and it is the legitimate process that is running. File-based scanning has no file to examine. Behavioural analysis sees activity attributed to a trusted binary. Privilege and access. Injecting into a process running with higher privileges, or one already holding credentials and open handles, grants those without exploiting anything further. Plausibility. Outbound connections from a browser process look entirely normal. The same connections from an unknown executable in a temporary directory do not. The techniques, roughly ...

SMB Explained: Versions, Signing, and Why SMBv1 Has to Go

Server Message Block is the protocol behind Windows file and printer sharing. It is also, by a wide margin, the protocol most often involved when something goes badly wrong on a Windows network — ransomware propagation, credential relay, and the worm outbreaks of recent years all traveled over it. Knowing its versions and its hardening settings is worth real exam points. What it does SMB is a client-server protocol for accessing files, printers, and named pipes on a remote host as though they were local. A client connects, authenticates, negotiates a dialect, and then issues open, read, write, and close operations against shares. Windows administrative shares such as C$ and ADMIN$ exist by default and are how most remote management tooling reaches a machine. Modern SMB runs directly over TCP 445. Legacy SMB rode on NetBIOS over TCP using 137, 138, and 139, which is why those ports still appear in hardening guides. Anchoring these in the wider set of port numbers to know is wo...