Reply to post: 'Zerologon' Windows domain admin bypass exploit released

What do F5, Citrix, Pulse Secure all have in common? China exploiting their flaws to hack govt, biz – Feds

sanmigueelbeer
Stop

'Zerologon' Windows domain admin bypass exploit released

'Zerologon' Windows domain admin bypass exploit released

The Zerologon flaw allows an attacker with a foothold on an internal Windows network to simply send a number of Netlogon messages, filling various fields with zeroes, and changing the Active Directory stored password of a Domain Controller.

Secura has also published a Python script on Github to test if a Domain Controller is vulnerable.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon