This article describes Windows Active Directory and the
possibilities of protection against attacks that threaten users
and the integrity of the company that uses this service. We have
analyzed in detail and experimentally implemented three types
of attacks: enumeration attack, Kerberos attack and password
spraying attack. All three attacks are directed against users
and in various ways obtain hashed values of passwords, which
attackers then convert into actual user passwords using bruteforce techniques. With the obtained passwords, unauthorized
individuals can gain access to network resources, increase
privileges and compromise the entire company infrastructure.
We also present appropriate preventive measures for server
protection and best practices for defense against such attacks,
such as correct configuration of Active Directory, strengthening password policy and introducing regular monitoring of
server security.
|