Ta spletna stran hrani piškotke, da bi vam zagotovili boljšo uporabniško izkušnjo in popolno funkcionalnost te strani.

Analitične piškotke uporabljamo s storitvijo Google Analytics, samo z vašo privolitvijo. Sprejemam Zavrnitev Več informacij

DPAPI and DPAPI-NG: Decrypting All Users’ Secrets and PFX Passwords

Predavanje je v angleškem jeziku.

CQURE Team takes DPAPI (Data Protection API) and DPAPI-NG research to the next level! During this session, you will hear about two great discoveries we made. The first one is about decrypting DPAPI-protected data by leveraging the usage of the private key stored as an LSA Secret on a domain controller (we have called it a ‘backup key’ and it is a key corresponding to the backup public key stored in the domain user’s profile). The backup key allows decrypting literally all of the domain user’s secrets (passwords / private keys / information stored by the browser). In other words, someone who has the backup key is able to take over all of the identities and their secrets in the entire enterprise. It is crucial to understand how this is happening! Another variant of DPAPI is DPAPI-NG. It is used in the SID-protected PFX files and while in the previous discovery CQURE Team was able to gain access to user’s secrets, here it is a bit different! Come to the session and discover how to decrypt SID-protected PFX files even without access to the user’s password, only by generating the SID and user’s token! We will present the team’s unique findings on how to gain access to users’ secrets by possessing the backup key from the domain and how to decrypt the PFX files passwords. Both demonstrations are key DPAPI breakthroughs that can cause serious implications if not managed well.

Paula Januszkiewicz

CQURE

Paula Januszkiewicz is the Founder and CEO of CQURE and CQURE Academy, companies she established back in 2008. She is also an Enterprise Security MVP, honorable Microsoft Regional Director, and a world-class cybersecurity expert, consulting Customers worldwide. In 2017, Paula graduated from Harvard Business School. She delivers keynotes and sessions at the biggest world conferences such as RSA, Black Hat, Microsoft Ignite, SecTor Canada, Australian Cyber Conference, GISEC, GITEX, LEAP, and many others. She is often a top-rated speaker, including being chosen as the No. 1 Speaker at Microsoft Ignite (among 1,100 speakers at a conference with 26,000 attendees) and at Black Hat Asia 2019. At the RSA Conference, two of her sessions were among the top 5 best rated. Paula is known for her unique stage presence that is always well-received among diverse audiences, often gathering thousands of people! Paula has over 19 years of experience in the cybersecurity field, performing penetration tests, architecture consulting, trainings, and seminars. Every year, she takes over 200 flights to provide cybersecurity services for CQURE’s Customers. Paula and her Team also design security awareness programs for various organizations, including awareness sessions for top management. Together, they create various security tools (CQTools) supporting penetration tests, incident response, and forensics, which are shared with the community. Paula is a member of the Technical Advisory Board at the Royal Bank of Scotland/Natwest. And to top it all off, she has access to the source code of Windows!

Komentiranje v NTK aplikaciji je mogoče za potrjene udeležence NT konference.

iPhone Android