paint-brush
Precious Tips To Protect Your Microsoft Account Password From Phishingby@ax

Precious Tips To Protect Your Microsoft Account Password From Phishing

by Ax Sharma3mSeptember 24th, 2020
Read on Terminal Reader
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

Security researcher bohops demonstrated a credential harvesting trick that uses Windows theme files. Setting a Windows wallpaper location to a file present at a remote location, for example, can be abused for phishing. Windows would automatically try to authenticate to a remote Samba location by sharing the user's NTLM hashes in the background to the remote server. The chances of the (unknown) remote resource or wallpaper or wallpaper sharing the same set of credentials are infinitesimally small. Microsoft stated they'd not be patching this bug as it was a "feature by design"

Company Mentioned

Mention Thumbnail
featured image - Precious Tips To Protect Your Microsoft Account Password From Phishing
Ax Sharma HackerNoon profile picture
Ax Sharma

Ax Sharma

@ax

Security Researcher, Engineer, Tech Columnist | https://hey.ax/

About @ax
LEARN MORE ABOUT @AX'S
EXPERTISE AND PLACE ON THE INTERNET.
L O A D I N G
. . . comments & more!

About Author

Ax Sharma HackerNoon profile picture
Ax Sharma@ax
Security Researcher, Engineer, Tech Columnist | https://hey.ax/

TOPICS

THIS ARTICLE WAS FEATURED IN...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite
Samtigis