| NTLM authentication: still broken after all these years |
| Source: The Register UK - Posted by Alex | ||
|
“The deeper problem is that NTLMv1-2 provide absolutely no protection against credentials forwarding/relay or reflection attacks,” Ray, who is a software developer at two-factor authentication service PhoneFactor, wrote in an email sent to journalists. “This means that an active attacker (such as a man-in-the-middle) is sometimes able to redirect the login of the legitimate user to authenticate his own session. Read this full article at The Register UK
Only registered users can write comments. Powered by AkoComment! |
||