Hackers Can Exploit 'Forced Authentication' to Steal Windows NTLM Tokens

Started by ixsky,

Previous topic - Next topic

ixsky

Hackers Can Exploit 'Forced Authentication' to Steal Windows NTLM Tokens

Cybersecurity researchers have discovered a case of "forced authentication" that could be exploited to leak a Windows user's NT LAN Manager (NTLM) tokens by tricking a victim into opening a specially crafted Microsoft Access file.
The attack takes advantage of a legitimate feature in the database management system solution that allows users to link to external data sources, such as a remote SQL

Source: Hackers Can Exploit 'Forced Authentication' to Steal Windows NTLM Tokens