Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

RC4 Is Still Considered Harmful

Summary

I've been spending a lot of time researching Windows authentication implementations, specifically Kerberos. In June 2022 I found an interesting issue number 2310 with the handling of RC4 encryption that allowed you to authenticate as another user if you could either interpose on the Kerberos network traffic to and from the KDC or directly if the user was configured to disable typical pre-authentication requirements.
Published
Collected

original ↗