Can hashes labeled ‘lm’ in SAM database mimikatz dump be another type than (NT)LM?

When I dump the password history hashes stored in the SAM database with mimikatz lsadump::dcsync tool, for every i’th password (re-)set by a SAM account there are two hashes stored by Active Directory (AD): ntlm- i and lm- i. I know storin… Continue reading Can hashes labeled ‘lm’ in SAM database mimikatz dump be another type than (NT)LM?

This Week in Security:Breaking CACs to Fix NTLM, The Biggest Leak Ever, and Fixing Firefox by Breaking It

To start with, Microsoft’s June Security Patch has a fix for CVE-2022-26925, a Man-In-The-Middle attack against NTLM. According to NIST, this attack is actively being exploited in the wild, so …read more Continue reading This Week in Security:Breaking CACs to Fix NTLM, The Biggest Leak Ever, and Fixing Firefox by Breaking It