Normal view
Checking those browsers
Podcast: Passwords: You Are the Weakest Link
![]()
Why are companies still recommending an 8-character password minimum?ย Passwords are some of the easiest targets for attackers, yet companies still allow weak passwords in their environment.ย Multiple service providers recommend [โฆ]
The post Podcast: Passwords: You Are the Weakest Link appeared first on Black Hills Information Security, Inc..
The Paper Password Manager
![]()
Michael Allen // Every year around the holidays I end up having a conversation with at least one friend or family member about the importance of choosing unique passwords for [โฆ]
The post The Paper Password Manager appeared first on Black Hills Information Security, Inc..
Webcast: Passwords: You Are the Weakest Link
![]()
Why are companies still recommending an 8-character password minimum?ย Passwords are some of the easiest targets for attackers, yet companies still allow weak passwords in their environment.ย Multiple service providers recommend [โฆ]
The post Webcast: Passwords: You Are the Weakest Link appeared first on Black Hills Information Security, Inc..
Passwords: Our First Line of Defense
![]()
Darin Roberts // โWhy do you recommend a 15-character password policy when (name your favorite policy here) recommends only 8-character minimum passwords?โ I have had this question posed to me [โฆ]
The post Passwords: Our First Line of Defense appeared first on Black Hills Information Security, Inc..
Finding: Weak Password Policy
![]()
David Fletcher// The weak password policy finding is typically an indicator of one of two conditions during a test: A password could be easily guessed using standard authentication mechanisms. A [โฆ]
The post Finding: Weak Password Policy appeared first on Black Hills Information Security, Inc..
An Open Letter about Big All-Powerful Companyโs Password Policy
![]()
Kelsey Bellew // Dear Big All-Powerful Company, Your idea of a โstrong passwordโ is flawed. When I first saw the following message, I laughed. I said out loud, โNo, you [โฆ]
The post An Open Letter about Big All-Powerful Companyโs Password Policy appeared first on Black Hills Information Security, Inc..
How to Bypass Two-Factor Authentication โ One Step at a Time
![]()
Sally Vandeven // Back in November Beau Bullock wrote a blog post describing how his awesome PowerShell tool MailSniper can sometimes bypass OWA portals to get mail via EWS if [โฆ]
The post How to Bypass Two-Factor Authentication โ One Step at a Time appeared first on Black Hills Information Security, Inc..
-
Black Hills Information Security
- How to Increase the Minimum Character Password Length (15+) Policies in Active Directory
How to Increase the Minimum Character Password Length (15+) Policies in Active Directory
![]()
Kent Ickler // As a start to a series on Windows Administration in the eyes of a security-conscious โWindows Guyโ I invite you on configuring AD DS PSOs (Password Security [โฆ]
The post How to Increase the Minimum Character Password Length (15+) Policies in Active Directory appeared first on Black Hills Information Security, Inc..
Lawrenceโs List 072216
Lawrence Hoffman // The list this week is a little shorter, I didnโt include a tool or POC link as I usually do. No particular reason, just didnโt run across [โฆ]
The post Lawrenceโs List 072216 appeared first on Black Hills Information Security, Inc..
-
Black Hills Information Security
- Question: ย What Can I Learn from Password Spraying a 2FA Microsoft Web App Portal?
Question: ย What Can I Learn from Password Spraying a 2FA Microsoft Web App Portal?
Carrie Robertsย // Answer:ย Enough to make it worth it! Penetration testers love to perform password spraying attacks against publicly available email portals as described hereย in this great post by Beau Bullock. [โฆ]
The post Question: ย What Can I Learn from Password Spraying a 2FA Microsoft Web App Portal? appeared first on Black Hills Information Security, Inc..
Lawrenceโs List 061016
Lawrence Hoffman // Itโs been one of those crazy busy weeks. I always feel like I didnโt get enough time to read articles, surf Reddit, and attempt to keep up [โฆ]
The post Lawrenceโs List 061016 appeared first on Black Hills Information Security, Inc..
10 Ways to Protect Your Online Digital Life
![]()
Joff Thyer // Recently I have been thinking about online challenges I encounter in daily life. ย As I thought about it, I realized that many of these items I [โฆ]
The post 10 Ways to Protect Your Online Digital Life appeared first on Black Hills Information Security, Inc..
Herding Those Pesky Passwords
Rick Wisser & Gail Menius // Frequently we get asked about where to store passwords. ย Should they be stored in a word/excel /txt file on your computer? Maybe, written down [โฆ]
The post Herding Those Pesky Passwords appeared first on Black Hills Information Security, Inc..
Passphrases for Tiny People
Gail Menius // Once upon a time, in a land not too far away (about two miles from where Iโm sitting now) I used to be an elementary school librarian. [โฆ]
The post Passphrases for Tiny People appeared first on Black Hills Information Security, Inc..
Check\ Your\ Tools
Brian King // Thereโs a one-liner password spray script that a lot of folks use to see if anyone on a domain is using a bad password like LetMeIn! or [โฆ]
The post Check\ Your\ Tools appeared first on Black Hills Information Security, Inc..
-
Black Hills Information Security
- Password Spraying Outlook Web Access โ How to Gain Access to Domain Credentials Without Being on a Targetโs Network: Part 2
Password Spraying Outlook Web Access โ How to Gain Access to Domain Credentials Without Being on a Targetโs Network: Part 2
![]()
Beau Bullockย // This is part two of a series of posts (See part 1 here)ย where I am detailing multiple ways to gain access to domain user credentials without ever being [โฆ]
The post Password Spraying Outlook Web Access โ How to Gain Access to Domain Credentials Without Being on a Targetโs Network: Part 2 appeared first on Black Hills Information Security, Inc..
-
Black Hills Information Security
- Exploiting Password Reuse on Personal Accounts: How to Gain Access to Domain Credentials Without Being on a Targetโs Network: Part 1
Exploiting Password Reuse on Personal Accounts: How to Gain Access to Domain Credentials Without Being on a Targetโs Network: Part 1
![]()
Beau Bullock // In this series of posts I am going to detail multiple ways to gain access to domain user credentials without ever being on a target organizationโs network. [โฆ]
The post Exploiting Password Reuse on Personal Accounts: How to Gain Access to Domain Credentials Without Being on a Targetโs Network: Part 1 appeared first on Black Hills Information Security, Inc..