Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

A Watchguard Vulnerability That's a "Feature" - GuardLapse

Summary

GuardLapse: WatchGuard's clientless AD SSO sends its AD account's authentication to any browsing device; a rogue SMB server can capture or relay the hash, reaching Domain Admin in one engagement.
Published
Collected

original ↗

Related coverage

back