Curious about how to exploit the latest ZeroLogon threat with Metasploit... and compromise an entire Active Directory domain in exactly 5 minutes? Well, watch this video!
ZeroLogon: https://cve.mitre.org/cgi-bin/cvename...
In the video, I demonstrate how to reset the password of the Domain Controller (DC) machine account in Active Directory. The password is reset to BLANK (= or an empty password). Once done, we have full control and can dump all the password hashes from AD.
BTW: don't try this at work.. but only at home (?), in a vulnerable test environment like in this video.
I have no intention of editing the video at this time: its main purpose is to discuss the topic in our classroom, and to provide former students extra training materials. However, please feel free to subscribe to this YouTube channel. The more subscribers, the more videos I will release...
Do you want to see and hack (~learn) more? Attend our Ethical Hacking BOOTCAMP training!
More: https://www.mmesec.com/training/ethic...