3 ms·
Cool approach, you need to compromise two separate servers just to have a usable password database you could run tools against. A key compromise can be fixed qu
by aomix 10y ago
Cool approach, you need to compromise two separate servers just to have a usable password database you could run tools against. A key compromise can be fixed quickly and a password compromise is useless without the key.
- dsl 10y agoOf the last 10 or so security engagements I have done, I can only recall one where I wasn't able to compromise _all_ servers. Once you get the first few, the incremental work to get everything is relatively small. When breaking in, your end goal isn't the database server... it's the domain controller or the configuration management server.