. NTLM - . ā Active Directory. company.ru, «» DNS-. , - , , - . ā NTLM (, ?), «» , . , . ā , . ā . ā , , . ā pass-the-hash-. ADFS .There is one bad feature of Microsoft products: even if you have not specifically published such NTLM, it will be in the default installation in OWA and Lync, at least.By the way, the author of this article once in the same way accidentally blocked approximately 1000 accounts of employees of one large bank in just one hour and then had a somewhat pale appearance. The bankās IT services were also pale, but everything ended well and adequately, we were even praised that we were the first to find this problem and provoked a quick and decisive correction.
Interestingly, the server was still trying to protect against MS17-010 - it had disabled vulnerable network services on the external interface. This really protects against attacks through the network, but the attack from within the localhost worked, since you cannot just take and quickly turn off SMB on localhost.
Then the VDI administrators shot themselves in the foot twice:The first time VDI machines were not brought into action by LAPS, essentially saving the same local administrator password from an image that was massively deployed to VDI.ā , pass-the-hash . , , ā .