Linchakin

Nosferatu - Lsass NTLM Authentication Backdoor

 November 19, 2021     No comments   

Lsass NTLM Authentication Backdoor


How it Works

First, the DLL is injected into the lsass.exe process, and will begin hooking authentication WinAPI calls. The targeted function is MsvpPasswordValidate(), located in NtlmShared.dll. In the pursuit of not being detected, the hooked function will call the original function and allow for the normal flow of authentication. Only after seeing that authentication has failed will the hook swap out the actual NTLM hash with the backdoor hash for comparison.

Usage

Nosferatu must be compiled as a 64 bit DLL. It must be injected using the a DLL Injector with SeDebugPrivilege.

You can see it loaded using Procexp:

Login example using Impacket:

Limitations

In an Active Directory environment, authentication via RDP, runas, or the lock screen does not work with the nosferatu password. Authentication using SMB, WinRM, and WMI is still possible.

In a non-AD environment, authentication works for all aspects.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • Patriot Viper VP4300 PCIe 4.0 SSD Quick Look: Easy PS5 Upgrade If you happen to be among the tens of people who bought one of Sony’s PlayStation 5 consoles at a regular retail store, for MSRP, and actually kept i… Read More
  • Build to Rent DAO: Pioneering the Concept of 'Rent-to-Earn' ‘digital nomads’ are mobile like never before; they can both move internally and across borders. They are pioneers of a new, ‘informational’ society.… Read More
  • How to Use Vanish Mode on InstagramVanish Mode is one of the best features on Instagram. It was added in 2021, and it has already become very popular. Vanish Mode allows user to hide th… Read More
  • Mitmproxy2Swagger - Automagically Reverse-Engineer REST APIs Via Capturing Traffic A tool for automatically converting mitmproxy captures to OpenAPI 3.0 specifications. This means that you can automatically reverse-engineer REST API… Read More
  • Top 10 Best Free VPN Services of 2022Best VPN Services 2022: VPNs are the best way to get you online security; access blocked websites, and much more. Virtual Private Network to call it i… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates