3 ms·
I'll take a look at this tomorrow, but it seems like a security researcher angling for a bug bounty. Cached local credentials and saved rdp credentials have ex
by kryogen1c 1y ago
I'll take a look at this tomorrow, but it seems like a security researcher angling for a bug bounty.
Cached local credentials and saved rdp credentials have existed for a long time and both have gpo settings to modify/disable - you just don't do it because no caching requires some kind of sase/ always on vpn, etc. I think most systems have disallowed rdp credential saving for years.
Furthermore, how does one connect to the domain with an invalid password? I'm inclined to think this was tested on a workgroup and not a domain. If you go long enough your trust tombstones and you lose all access anyway, cached and saved or not.