|
|
|
|
|
by jabroni_salad
1249 days ago
|
|
Kinda wish legacy protocols made an appearance. plaintext ldap, unsigned SMB, SMBv1 still being enabled somehow, DHCPv6 poisoning, llmnr, netbios, kerberoast. These are the responsible party for like 90% of pentest reports that I have personally seen. Also while I am soapboxing I just wanna say that nearly all corporate security issues are actually just operations issues, like patch management and config management. Everything I listed above can be solved by a single sysadmin with group policy and 30 minutes to kill, and they wont reoccur. In the sysadmin sphere there is a tendancy to treat security concerns as their own industry. You don't need your kitchen staff to be microbiologists to know that they should wash their hands and you don't need your sysadmin to be a CISSP to know to disable protocols that you arent using. Just IMO as a consultant who straddles the fence. |
|
It is what MIGHT happen after.
That critical ERP/Invoice/Fileshare Server 2003 and the business critical printer from 2001 might still need SMBv1.
NETBIOS is still used in modern stuff, no?
We can't really just disable it willy-nilly.
>Everything I listed above can be solved by a single sysadmin with group policy and 30 minutes to kill, and they wont reoccur.
Yes, every L2 IT helpdesk can push a GPO out. It's what the GPO does that is the issue.