GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Lars Karlslund :verified: (lkarlslund@infosec.exchange)

  1. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Wednesday, 13-Dec-2023 04:48:25 JST Lars Karlslund :verified: Lars Karlslund :verified:

    I've been tinkering with 8.7 billion passwords the last couple of weeks - and done lots of thinking, coding and debugging too. This resulted in a cool thing that I'm sharing today.

    Here's the technical background: On the Windows platform your stored passwords are hashed as NTLM, which is basically just a Microsoft way of saying "MD4 sum of the UTF16 encoded password". As this was invented more than 25 years ago, this algorithm is simple.

    Here's why this matters: When hackers break into your network, both configuration mistakes and weak passwords are in the very top of risks that enable a successful way for bad guys to get control over everything.

    This is how you can remedy this: When I do Active Directory assessments, some of the time I also do a password audit, to find accounts that use the same password or highly privileged accounts with way too simple passwords. And I don't really care about regular users, but the ones that impact security do matter.

    This is the challenge: To crack these passwords requires equipment and machine power, as going from an NTLM hash to a password is not something you can do by other means than throwing some GPU power after it. You simply try any password you can imagine, and compare it to the NTLM hash - it takes some time, and you don't get all passwords (complex ones survive these attacks).

    And here's my solution: There is a faster way - maybe not providing you with exactly the same results - but it trades some of the precision with less time and hardware required. Because NTLM hashing is "unsalted", it means that the password 123456 will have the exact same hash on any system you encounter in the world. So why not just look the most obvious ones up in a database?

    Now you can, because I coded up a specialized database, grabbed everything I could find from leaks, dictionaries and wordlists on the internet, and compiled it up for you.

    It's free to use, there is no sign up required - and you can look up 1 password every second (batch look up 1000 in a few seconds every 15 minutes if you're in a hurry). It's even easy to use from command line using curl or PowerShell if you're into that.

    Have fun, and I hope it can help make the world safer a little step at a time. If you like this, please re-share and spread the word (not the password!)

    https://ntlm.pw/

    In conversation Wednesday, 13-Dec-2023 04:48:25 JST from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Servizio in corso di attivazione
    2. Domain not in remote thumbnail source whitelist: ntlm.pw
      NTLM to plaintext password lookup
      Instantly look up NTLM hashes and resolve them to plaintext passwords using our database with 8B+ entries.
  2. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Tuesday, 28-Nov-2023 19:49:51 JST Lars Karlslund :verified: Lars Karlslund :verified:

    For Adalanche users:

    I'm very unsure whether adding every account in an AD to the "Authenticated Users" group was a good decision or not. It does show the massive impact this group has, but it also clutters large graphs.

    Any input?

    In conversation Tuesday, 28-Nov-2023 19:49:51 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/487/711/194/468/855/original/3cc7035eb2e318bd.png
  3. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Sunday, 09-Jul-2023 02:14:39 JST Lars Karlslund :verified: Lars Karlslund :verified:
    in reply to
    • Jake Hildreth (acorn) :blacker_heart_outline:

    @horse @ChrisTruncer yes, there's an option to do that in the LDAP library in my fork, not sure if they implemented that in the main one. In my commercial version I've implemented the Windows API, but unfortunately that's not open source

    In conversation Sunday, 09-Jul-2023 02:14:39 JST from infosec.exchange permalink
  4. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Tuesday, 13-Jun-2023 01:45:11 JST Lars Karlslund :verified: Lars Karlslund :verified:
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller just like the rest of us

    In conversation Tuesday, 13-Jun-2023 01:45:11 JST from infosec.exchange permalink
  5. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Sunday, 11-Jun-2023 08:46:30 JST Lars Karlslund :verified: Lars Karlslund :verified:

    My 2nd attempt at a parallel robotic gripper now features a pressure banana - how kinky is that

    In conversation Sunday, 11-Jun-2023 08:46:30 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmediaeu/media_attachments/files/110/522/307/860/848/518/original/c831391dd8f2c39d.png
  6. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Sunday, 11-Jun-2023 08:46:29 JST Lars Karlslund :verified: Lars Karlslund :verified:
    in reply to

    I really wish I knew what I was doing.

    Like all the time.

    In conversation Sunday, 11-Jun-2023 08:46:29 JST from infosec.exchange permalink
  7. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Friday, 21-Apr-2023 18:43:33 JST Lars Karlslund :verified: Lars Karlslund :verified:

    "Do we have an adapter that changes the one that's missing one corner to the one that's missing two corners?"

    In conversation Friday, 21-Apr-2023 18:43:33 JST from infosec.exchange permalink
  8. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Tuesday, 31-Jan-2023 23:03:42 JST Lars Karlslund :verified: Lars Karlslund :verified:

    A friend gave me a broken laptop, with no clear problem description. There was no charger, so after rummaging around in my stuff, I found an HP charger that should work. The laptop was fine, but even though it said "charging" and had s an orange LED the battery stayed in 0% ... Reinstalling, BIOS update etc. didn't help, and the only stuff on YouTube was garbage. So it either the battery or the motherboard. Let's disassemble the battery!

    In conversation Tuesday, 31-Jan-2023 23:03:42 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/777/798/110/101/796/original/f3094320ac0652c5.jpg

    2. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/777/812/083/477/965/original/0854e87e18092cc9.jpg
  9. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Tuesday, 31-Jan-2023 23:03:40 JST Lars Karlslund :verified: Lars Karlslund :verified:
    in reply to

    So measuring voltage across the cells shows 0V output from the battery, and 1.2V across all cells (they should be around 12V to 16V). So the battery collapsed, it could still be the motherboard though. Anyway, I'm replacing the cells with some others I pulled from some laptops. After removing the old ones, I carefully weld new-old ones back.

    In conversation Tuesday, 31-Jan-2023 23:03:40 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/777/821/257/161/397/original/99c3c6627440785e.jpg

    2. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/777/822/073/364/397/original/05fe1e32e1cd32f8.jpg
  10. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Tuesday, 31-Jan-2023 23:03:39 JST Lars Karlslund :verified: Lars Karlslund :verified:
    in reply to

    This is my very much improvised battery welder. It's the transformer from a microwave, some heavy duty wire and a Sonoff wifi switch which I've programmed to switch on for 200ms and then off when I press the black button. Very ghetto, but it works really great.

    In conversation Tuesday, 31-Jan-2023 23:03:39 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/777/825/901/124/410/original/0eef0bec0ed2dd42.jpg

    2. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/777/826/238/787/059/original/b9dcf2c59290eb81.jpg

    3. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/777/826/425/671/773/original/f1a6d16f0b827cf4.jpg
  11. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Tuesday, 31-Jan-2023 23:03:34 JST Lars Karlslund :verified: Lars Karlslund :verified:
    in reply to
    • verb (printfJess) ?

    @verb battery welder! It transforms the 230V AC down to 2V or so, just with a huge amount of amps. It welds nickel tabs to the end of batteries, mostly without the risk of dying while you use it. There are lots of instructions on how to build this on the internet.

    In conversation Tuesday, 31-Jan-2023 23:03:34 JST from infosec.exchange permalink
  12. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Monday, 09-Jan-2023 03:32:27 JST Lars Karlslund :verified: Lars Karlslund :verified:

    OMG how have I been shaving all these years without this?

    In conversation Monday, 09-Jan-2023 03:32:27 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/654/991/997/820/066/original/115599a920f42ee2.png
  13. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Tuesday, 13-Dec-2022 09:59:01 JST Lars Karlslund :verified: Lars Karlslund :verified:
    in reply to
    • Alyssa Miller ?️​ :nyancat_rainbow: :donor: ​

    @alyssam_infosec this is a cat parent problem, not a cat problem :-)

    I can recommend screwing a hook into the ceiling, and wire the tree to the hook. We have two cats, and no toppled trees ever. Super simple fix!

    In conversation Tuesday, 13-Dec-2022 09:59:01 JST from infosec.exchange permalink
  14. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Wednesday, 30-Nov-2022 22:19:09 JST Lars Karlslund :verified: Lars Karlslund :verified:
    • Jake Hildreth (acorn) :blacker_heart_outline:

    Do you want to spend December getting familiar with a new programming language, but not sure where to start?

    Advent Of Code offers daily puzzles, which you can solve using any programming language.

    (Maybe that's how you'll become familiar with Go, @horse?)

    https://adventofcode.com/2022/

    In conversation Wednesday, 30-Nov-2022 22:19:09 JST from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Advent of Code 2022
  15. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Monday, 28-Nov-2022 19:41:28 JST Lars Karlslund :verified: Lars Karlslund :verified:

    Adalanche: Improved Domain Controller auto-detection and selection in Adalanche.

    You can now supply a list of servers on the command line, or Adalanche will detect them from DNS itself. Then it tries to connect to each of them in turn, until it finds a usable one.

    It doesn't honor the Sites & Services lookup yet, but this should work fine until then.

    It should probably handle different errors differently, i.e. login errors should just error out instantly. Feedback is welcome!

    #adalanche -> https://github.com/lkarlslund/Adalanche

    In conversation Monday, 28-Nov-2022 19:41:28 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/420/303/313/375/909/original/2d23ced0acbf137f.png
    2. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      GitHub - lkarlslund/Adalanche: Active Directory ACL Visualizer and Explorer - who's really Domain Admin? (Commerical versions available from NetSection)
      Active Directory ACL Visualizer and Explorer - who's really Domain Admin? (Commerical versions available from NetSection) - GitHub - lkarlslund/Adalanche: Active Directory ACL Visualizer and Ex...
  16. Embed this notice
    Lars Karlslund :verified: (lkarlslund@infosec.exchange)'s status on Monday, 14-Nov-2022 08:07:41 JST Lars Karlslund :verified: Lars Karlslund :verified:

    Twitter queen of graphql doesn't take any shit

    In conversation Monday, 14-Nov-2022 08:07:41 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmedia/media_attachments/files/109/338/839/583/025/549/original/8415b54ba35b43db.png

User actions

    Lars Karlslund :verified:

    Lars Karlslund :verified:

    Curious security octopus | Active Directory Nerd | Adalanche AD Attack Graph Analyzer | Sarcasm level 10 | Fond of LEGO

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          22686
          Member since
          10 Nov 2022
          Notices
          16
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.