Posts

Showing posts from July, 2020

What the hec... no... Hack The Box?

Image
If you have always wanted to break boxes but don't have a clue where to start, Hack The Box may be The Service(tm) for your weird tastes. And that's why I subscribed there. :) It's basically a service which offers various virtual machines with various difficulty levels regarding hacking. The easiest ones are really easy, and the insane ones on the other side of the scale are just like that. You can choose between free and paid versions. The biggest differences between these two plans are that only the paid one offers also the retired machines and virtual machines there have more resources available. And you are not allowed to publish howtos or walkthroughs for the active machines. So if you want to learn faster(?) or more, you probably want to get the paid plan at least for first few moons. By doing that you can get help when you'll get stuck. Yes, there are also other resources available but you can read more from their website. But, now I wanted to show what it actua...

Insecure defaults in Windows + NPS / Active Directory

Disclaimer: I got some comments that some descriptions etc. are a bit "vague". But it's on purpose.  I don't want to (or can't) reveal too much information regarding the actual real life setup. It's sometimes quite difficult to do, to walk on the fine line between too little and too much information. Thus I try to always find the essence of the issue on hand, but I also understand that it means quite often that some important information may be missing. I may update some posts when enough years have passed and that particular information is not too critical any more. But I won't promise anything! ;) Microsoft Network Policy Server , NPS. *sigh* Another *sigh* Did I already convinced you that I don't love this product? This text is about the annoying and problematic defaults you'll find everywhere in Microsoft products. I'm not sure whether they value backward compatibility over everything else or if they just don't know what they are using ...