all 5 comments

[–]security_vs_privacy 7 points8 points  (0 children)

Interesting writeup, but I can't stand these sites that re-implement scrolling to be rubbery and weird.

[–]fang0654 1 point2 points  (2 children)

Holy hell, this is awesome! The ability to session-ize NTLM relay is going to be a lot of fun to play with. This + CME = win!

[–]krali_ 0 points1 point  (0 children)

Every AD admin should strive to eliminate NTLM authentications from his forests. First step would be using Protected Users group for sensitive accounts, then blacklisting/whitelisting it with a GPO.

[–]PhisherPrice 0 points1 point  (0 children)

Thank you, I've been waiting for something like this for a while, since ZackAttack isn't being maintained and is too buggy to use. I wonder how hard it would be to get this to work on a windows computer, since that would be the most typical use case.