4 ms·
> For a Golden SAML attack, an adversary must first compromise the AD FS service account on the AD FS server. Then it was game-over from the beginning... Nothi
by lelag 3y ago
> For a Golden SAML attack, an adversary must first compromise the AD FS service account on the AD FS server.
Then it was game-over from the beginning... Nothing surprising about this and it's not really a weakness of SAML either...
It's like saying a lock is insecure because if you manage to steal the key, you can open it...
- sillystuff 3y agoIt sounds like the initial compromise is easier than it should be, though (I can't believe that after 20 years of known issues of accepting a password hash as password equivalent in MS Windows, that MS is still making this mistake?!! > The example below uses a few techniques: LDAP reconnaissance to discover AD FS, DCSync to export the service account’s hashes, and then Pass the Hash (PtH) to gain a session on the AD FS Server as the service account.
- jpitz 3y ago"It rather involved being on the other side of this airtight hatchway" - Raymond Chen
- halJordan 3y agoYes, but also no. There's nothing inherently wrong with describe the types of keys that are stealable. Especially if it leads to mitigations. To your point, complaining about reporting on golden tickets is like complaining when a locksmith talks about his new lockpicking methods. Of course if a locksmith ever gets to the lock it's already over, so why let them even speak?