DEMO: Microsoft telnet client MS-TNAP server-side authentication exploit.

Опубликовано: 29 Июль 2026
на канале: liminalsecurity
12
0

DEMO TELNETCLIENTPOC.EXE
https://github.com/hackerhouse-openso...
From the github page:
This proof-of-concept demonstrates a vulnerability in the Microsoft Telnet Client's MS-TNAP authentication protocol. When a client connects to a malicious Telnet server via telnet.exe or telnet:// URI hyperlinks, and the MS-TNAP extension is detected, the server can extract authentication material from the client. If the exploit is run by a host in the Intranet or Trusted Zone, the credentials are sent automatically without prompting, making this practical for Red Team uses.

CONTENT:
created by limsec for educational purposes.

READING:
https://deepwiki.com/hackerhouse-open...

TAGS:
#activedirectory #hacking #linux #windows #kerberos #pentesting #cybersecurity