Certified Vulnerable: How Certificates Can Be Exploited

12/06/2023 29 min Temporada 1 Episodio 19
Certified Vulnerable: How Certificates Can Be Exploited

Listen "Certified Vulnerable: How Certificates Can Be Exploited"

Episode Synopsis

A discussion with ITAL members Eric Brown and Scott Rysdahl with Micah Kryzer. Micah is a pentester by day but also works alongside the ITAL team. In this episode the crew overviews certificates, a big topic that transcends any one vendor or environment. Certificates are like an electronic passport meant to uniquely identify a person, computer or application on a network. This specific family of vulnerabilities discussed affects the Microsoft Active Directory certificate services, which is Microsoft’s own built-in PKI or public key infrastructure included with Window’s servers and domains. Micah walks us through a pentest demo illustrating the ways this system can be exploited as well as providing tips on how to protect business networks from this attack. 

More episodes of the podcast The Audit - Cybersecurity Podcast