Sven Hertle

42 Followers
162 Following
7 Posts
Pentesting, Cloud Security, Red Teaming. Security Consultant @ HvS
Githubhttps://github.com/svenhertle
Websitehttps://svenhertle.net
Twitterhttps://twitter.com/svenhertle
CityMunich
Aus gegebenem Anlass: Wenn die Datenschützer:innen schuld an den Cookie-Bannern seien sollen, warum haben dann die Website und Apps von Datenschützer:innen keine Cookie-Banner?
Here we go. #37c3
When your patch management solutions destroys itself and you fix it via Defender for Endpoint Live Response…
Don’t forget to increment the year in your password!
Maybe I‘m a bit late to the CVE-2022-37958 party (that SPNEGO thing): Remote Desktop Gateway and especially the RDWeb component configure IIS so that Windows authentication with the Negotiate provider are enabled for some endpoints. Check for example /RDWeb/FeedLogin