Тёмный

Phishing The Resistant: Phishing For Primary Refresh Tokens In Microsoft Entra - Dirk-Jan Mollema 

DEFCON Switzerland
Подписаться 1,7 тыс.
Просмотров 2,1 тыс.
50% 1

Dirk-Jan Mollema (Outsider Security)
Microsoft Entra ID (formerly Azure AD) offers many options to harden your tenant against attackers.
Most of these options are enforced using Conditional Access policies, which for example allow you to restrict users to authenticate with only phishing resistant MFA methods such as Yubikeys and Windows Hello for Business. These MFA methods are resistant against common attacks, such as attacker-in-the-middle attacks via fake login pages, because they will only authenticate against the real Microsoft websites. There is however a catch: the provisioning of such MFA methods is often done from scenarios where such strong authentication cannot be enforced, such as during the device setup. In this talk we will see that by phishing for regular refresh tokens, using some tricks that Microsoft uses during the Windows installation, we can actually obtain a Primary Refresh Token and even provision these Phishing Resistant authentication methods by ourselves. The talk will also cover new mitigations that Microsoft introduced to combat these attacks, and what you can do to protect your tenant.

Наука

Опубликовано:

 

3 июл 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 1   
@kalidsherefuddin
@kalidsherefuddin 12 дней назад
Thanks
Далее
Where People Go When They Want to Hack You
34:40
Просмотров 1,3 млн
Phishing Resistant MFA How it Works!
15:26
Просмотров 11 тыс.
Insane Vulnerability In OpenSSH Discovered
1:06:56
Просмотров 167 тыс.
FIDO Promises a Life Without Passwords
9:58
Просмотров 397 тыс.
3 Levels of WiFi Hacking
22:12
Просмотров 1,7 млн
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
100+ Linux Things you Need to Know
12:23
Просмотров 779 тыс.
Colorful Vulcan w rtx 4070ti Super
13:30
Просмотров 60 тыс.