However, we had not managed to gain access to the password manager of the internal IT. We already achieved the goals from Domain Administrator to Global Admin for the Azure-Cloud and access to protected networks. With the highest privileges, it is just a matter of time before the attacker reaches his given goal. In order to make the criticality of the found vulnerabilities clear, we usually show the customer the worst case - if agreed. If you find and open a password protected Excel-Sheet it will look like this:Ġx23353435 and me were at a customers environment for an internal penetrationtest earlier this year. This can be done under the File -> Info -> Protect Workbook -> Encrypt with Password tab: This post will show how to attack such szenarios and why people should not use this method for password storage.Įxcel gives users the option of assigning a password to the sheet so that it is protected from unauthorized access. They were using a password protected Excel-file as password manager. It was made during an engagement at a customers environment. This post will cover a little Excel Macro project by and me. Excel-Phish - Phish protected Excel-file passwords | S3cur3Th1sSh1t Home About Excel-Phish - Phish protected Excel-file passwords December 15, 2020
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |