joe

1.7K posts

joe banner
joe

joe

@joewaredotnet

Former Microsoft DirSvc MVP (15+years), published author (still poor), nerd (duh), purveyor of nonsense, eternal optimistic cynic. Only 160 chars? Are you insa

Somewhere in Michigan Katılım Eylül 2012
249 Takip Edilen826 Takipçiler
joe
joe@joewaredotnet·
@MacmodSec They don't tend to document their bugs (because the dev didn't know it was a bug) or when they do stupid things like not validating input. :D
English
0
0
1
24
Artur Marzano
Artur Marzano@MacmodSec·
@joewaredotnet The catch is that AD doesn't validate that the timezone is composed of bytes between 0x30 and 0x39, and calculates the offset using a formula that can be overflown :) I'm not going to share it yet to let others play, but it's funny that you can't find that anywhere in MS docs :P
English
1
0
0
71
Artur Marzano
Artur Marzano@MacmodSec·
Quick christmas challenge - if you run the magic query (whenCreated>=21180101000000.+/959) in ANY Active Directory environment it will perform a full object dump. Why? :)
English
4
0
10
1.8K
joe
joe@joewaredotnet·
@MacmodSec The query date that results from the bug with 21180 is November 1981. I lived through 1981. :) 2024 works even better. Both are moot. Anything after the + (or -) should be a valid string integer value of HHMM **OR** should result in an UNDEFINED query.
English
1
0
0
88
Artur Marzano
Artur Marzano@MacmodSec·
@joewaredotnet It's definitely a bug, but it can be understood and replicated if you look closely. The query was specifically chosen to cause the date to precede AD, even though it's years in the future
English
1
0
0
83
joe
joe@joewaredotnet·
@SamErde I'd like to thank the academy. It's an honor just to be nominated. 😹
English
1
0
4
36
Sam Erde
Sam Erde@SamErde·
Putting legit operations tools like ADFind, PuTTY, and WinSCP under the heading of "Commodity Malware" in a joint cybersecurity advisory feels sensational and irresponsible. (Did Forbes write this?! ) 😋 They might as well include Bash, PowerShell, & git! #page7" target="_blank" rel="nofollow noopener">ic3.gov/Media/News/202…
Sam Erde tweet media
English
19
31
185
17.6K
Leo D'Arcy
Leo D'Arcy@LeoDArcy1·
@joewaredotnet @NerdPyle I would also point out that if you have domain controllers hosted in Azure it's as easy to compromise the domain from the Azure plane as it is using Arc for on-prem. It's why you always want to put DCs in a separate subscription and limit the RBAC
English
2
0
1
159
joe
joe@joewaredotnet·
@NerdPyle I have been thinking what I would most want out of AD, it comes down to better logging for client connections so I don't have to use wireshark to find things like SSL/TLS/Other info. And proper Property Sets, I should be able to put an attribute into multiple Property Sets.
English
2
0
5
138
joe
joe@joewaredotnet·
@NathanMcNulty @NerdPyle Yep thankyou. :) Aware and was involved in raising the issue to MSFT last year, still not thrilled with the awkward position MSFT is bending me over into. :)
English
1
0
6
271
Nathan McNulty
Nathan McNulty@NathanMcNulty·
@joewaredotnet @NerdPyle Just in case you haven't seen it yet, we do have some controls to limit risk a little #local-agent-security-controls" target="_blank" rel="nofollow noopener">learn.microsoft.com/en-us/azure/az… I'm still not a fan of a cloud management plane for my on-prem DCs, but when forced to...
English
4
2
16
1.2K
joe
joe@joewaredotnet·
@Ford who in the world thought that the domain email-ford.com was a good idea? Use subdomains so people don't have to investigate the domain to see if some bad actor registered it so they know if an email is legit or not. Just clueless.
English
0
0
0
7
joe
joe@joewaredotnet·
I hate when one of the bugs I find is me not reading my own tool usage properly. It also means I failed on the intuitiveness of a given switch. Double fail. I mean you can't win them all, but still I hate fails even though I know and understand you find success through fails.
English
0
0
4
330
joe
joe@joewaredotnet·
@elonmusk Dude, all due respect, you need to focus on what you are trying to run and less on what others are running. Ripping on FB does nothing to help your company get better. Once the news and magazine articles are all talking about how amazing X/Twitter has become, then talk shit.
English
0
0
1
64
Paul Asadoorian @paulasadoorian@infosec.exchange
I want to create one of those "fixer-upper" shows, but instead of homes, we'll come in and renovate your server room. I just can't think of an excellent name for the show...
Paul Asadoorian @paulasadoorian@infosec.exchange tweet media
English
476
124
1.9K
286K
Justin Elze
Justin Elze@HackingLZ·
@securityweekly Wow a retro show! The kids are making shows about moving to the cloud 😂
English
2
0
19
5.4K
joe
joe@joewaredotnet·
Entra? Not great, not even good. Way better than Azure Active Directory though since it isn't Active Directory in any way shape or form and never was. Hopefully this will clear up some confusion for some people. I recommend people just call it MCI. Microsoft Cloud Identity.
English
0
0
5
388