Suivre

Backdoor Office365 and Microsoft AD by stealing AD FS certificate/key pair. Golden SAML attack will allow an attacker to:

  • Bypass MFA to Azure / Office365
  • Logon as any AD user regardless of password resets
  • Method is usually valid for a year

inversecos.com/2021/09/backdoo

Inscrivez-vous pour prendre part à la conversation
nanao

Comme le soleil, les machines ne se couchent jamais.