Archives by Tag 'NTLM'

Windows Server SMB Authentication Rate Limiter

By Andrei Ungureanu - Last updated: Sunday, March 20, 2022

A small but cool feature is available in the new insider version of Windows Server (soon to be available on Windows 11 too) called SMB Authentication Rate Limiter. This will slow down NTLM brute force attacks against SMB servers and will be a good protection for those small environments where advanced analytics and monitoring are […]

How NTLM authentication works

By Andrei Ungureanu - Last updated: Tuesday, February 23, 2016

Despre Kerberos se tot vrobeste insa sunt multe cazuri in care ne confruntam si cu NTLM iar pentru a diagnostica problemele de autentificare e bine sa intelegem si cum functioneaza. Mai jos sunt etapele procesului de autentificare: (Interactive authentication only) A user accesses a client computer and provides a domain name, user name, and password. […]

Forcing NTLM authentication in Internet Explorer

By Andrei Ungureanu - Last updated: Thursday, May 30, 2013

De curand am tot vazut erori legate de autentificarea Kerberos si probleme cu SPN-ul definit pe computer account sau probleme cu modul in care este accesat un server. Si am vazut cazul in care cineva incearca sa se autentifice din IE la un server, sa zicem server1.contoso.com dar folosind o alta inregistrare DNS gen server2.contoso.com. […]

Network access validation algorithms NTLM/SMB

By Andrei Ungureanu - Last updated: Thursday, October 11, 2012

Rasfoind prin KB-urile de la MS am gasit unul foarte interesant. Chiar daca se refera doar la XP/2003/2000 inca mai e util in unele scenarii de troubleshooting. http://support.microsoft.com/kb/103390 Gasiti aici explicate cateva scenarii plus algoritmul parcurs in procesul de autentificare. Este high level dar totusi foarte util. Mai ales in scenarii de workgroup.