- ’PetitePotam’ ADCS Domain Admin Vulnerability
- This one come from Bojan Zdrnja (@bojanz) and a great diary he posted to ISC about the entire issue.
- Bojan’s piece is a must-read to wrap your head around everything going on.
- At the core is NTLM (New Technology LAN Manager) relay, in which an attacker has a “machine-in-the-middle” position and is able to intercept credentials being sent. This gets into Microsoft’s encrypted file system remote protocol, and no further authentication is required, making matters worse.
- Summed up, Don’t use NTLM for authentication! Particularly, on Active Directory Certificate Services, make sure that IIS is not allowing authentication via NTLM.
- Mitigation documentation from Microsoft here.
- More coverage also from Bleeping Computer.
- VidMe Domain Owner Change Causes Major News Sites to Show Pornography
- This one is causing quite the kerfluffle including, we believe, the New York Times, Washington Post, and Huffington Post temporarily showing adult-themed content temporarily on their sites.