A Watchguard Vulnerability That's a "Feature" - GuardLapse
projectblack.io | vulnerability | #active-directory | #smb | #sso | #ntlm-relay | #watchguard | #guardlapse
Summary
GuardLapse: WatchGuard's clientless AD SSO sends its AD account's authentication to any browsing device; a rogue SMB server can capture or relay the hash, reaching Domain Admin in one engagement.
- Published
- Collected
Skip to content