Facebook Twitter Instagram
    Facebook Twitter Instagram
    The Conservative NutThe Conservative Nut
    Subscribe
    • Home
    • Latest News
    • Politics
    • Videos
    • Events
    • Others
      • Entertainment
      • Technology
      • Science
      • Business
    The Conservative NutThe Conservative Nut
    Home » Azure Active Directory: vulnerability allows brute force attacks against credentials
    Technology

    Azure Active Directory: vulnerability allows brute force attacks against credentials

    By David SOctober 20, 20212 Mins Read
    azure-active-directory:-vulnerability-allows-brute-force-attacks-against-credentials

    The flaw was discovered in June by Counter Threat Unit (CTU, but not that of 24 h Chrono) researchers from SecureWorks. It “ allows malicious actors to carry out single-factor brute force attacks against AAD without generating connection events ”, when the Seamless Single Sign-On service is enabled .

    In short, this means that hackers can try as many times as they want to guess a password. The infrastructure does not log attempts, letting them do it and start over without anyone being alerted.

    The problem, according to the researchers, lies in the use made of the Kerberos protocol, often used by Microsoft for everything related to SSO. As explained by Ars Technica, some predicted error codes are incorrectly recorded, paving the way for attack scenarios.

    According to the researchers, the mechanism could be used in any which company using Microsoft 365 or Azure Active Directory, including those using Pass-through Authentication (PTA).

    However, SecureWorks only classifies this vulnerability as “medium” dangerousness. Ease of operation actually stems directly from the complexity of the password: just because a breach allows brute force to do so does not mean that a word will be easily found. Brute force attacks are expensive.

    Still according to the researchers, Microsoft would have responded that this was intended behavior. In other words, it wouldn’t be a bug, but a function. The company did not respond to requests from Ars Technica.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    David S

      Related Posts

      Xfinity Blinking Orange Light: What Does It Mean?

      October 28, 2022

      How to Cancel Peacock TV on Roku

      October 27, 2022

      Insignia TV Remote Not Working: How to Fix?

      October 27, 2022

      How to Get FeelSafe Wireless Free Government Phone

      October 26, 2022

      Optimum Internet Plans for Existing Customers

      October 25, 2022

      How To Get a Free Laptop From Amazon [Easy Steps]

      October 25, 2022
      Add A Comment

      Comments are closed.

      Don't Miss
      News

      A couple of autocrats trolled Donald Trump

      November 30, 2022

      Former President Donald Trump had arranged a private dinner with the American Rapper Kanye West,…

      McConnell says Trump ‘unlikely’ to win after hosting Fuentes

      November 30, 2022

      Donald Trump won’t rally for Herschel Walker before runoff

      November 30, 2022

      DeSantis keeps ‘ignoring Trump’ as he starts the 2024 campaign

      November 30, 2022
      Stay In Touch
      • Facebook
      • Twitter
      • Pinterest
      • Instagram
      • YouTube
      • Vimeo
      Facebook Twitter Instagram Pinterest
      • About Us
      • Contact Us
      • Advertise With Us
      • Editorial Policy
      • Privacy Policy
      • Affiliate Disclosure
      © 2022 TCN

      Type above and press Enter to search. Press Esc to cancel.