Monday, June 29, 2026
World News Prime
No Result
View All Result
  • Home
  • Breaking News
  • Business
  • Politics
  • Health
  • Sports
  • Entertainment
  • Technology
  • Gaming
  • Travel
  • Lifestyle
World News Prime
  • Home
  • Breaking News
  • Business
  • Politics
  • Health
  • Sports
  • Entertainment
  • Technology
  • Gaming
  • Travel
  • Lifestyle
No Result
View All Result
World News Prime
No Result
View All Result
Home Business

Have You Seen My Domain Controller?

December 15, 2025
in Business
Reading Time: 3 mins read
0 0
0
Have You Seen My Domain Controller?
Share on FacebookShare on Twitter


At Cisco Dwell Melbourne 2025, the SOC noticed many attention-grabbing behaviors from the assorted purchasers of the convention community.  One of many extra attention-grabbing ones was observations pertains to the DNS site visitors emitted by Home windows purchasers on the community, in search of their group’s Lively Listing Area Controllers.  With our Endace full packet seize for the occasion, we had been capable of seize DNS site visitors from purchasers on the community and carry out evaluation utilizing Splunk Enterprise.

As a reminder, when a Home windows consumer is searching for to speak to a site controller it would make DNS queries for SRV information for names like _kerberos._tcp.dc._msdcs.DOMAINNAME or _ldap._tcp.dc._msdcs.DOMAINNAME.  These DNS requests allow the consumer to search out close by Kerberos or LDAP servers for his or her area. 

Within the Cisco Dwell Melbourne 2025 SOC, we noticed purchasers ship out DNS queries for about 3,800 distinct names beginning with “_ldap” or “_kerberos”.  Whereas most of them returned a failure of some kind (NXDOMAIN or SERVFAIL), roughly 300 had a profitable DNS response.  A few of these had been profitable in subsequent makes an attempt to hook up with the service (that means the area controllers are accessible in some trend from the general public web), and some had been adopted up by cleartext LDAP BINDs, leaking credential info throughout the native community and Web.  (SEE DANIEL’S BLOG POST)

Duane - redacted ldap and kerberos queries

There are a number of issues to contemplate from this.

First, there’s an open-source intelligence (OSINT) side to this.  The operators of any wi-fi community that you simply connect with along with your laptop computer acquire telemetry about your group.

Second, a malicious wi-fi community may – relying on how your purchasers are configured – trick the consumer into sharing authentication info with it.  Instruments corresponding to Responder are designed for this goal.  Correctly configured trendy Home windows purchasers will use SMB signing, LDAP over TLS, LDAP channel binding, and different types of safety in opposition to a hostile community atmosphere.  Are you positive your purchasers are configured in a manner that makes them sturdy in opposition to a hostile community?

Third, in case your group has Lively Listing area controllers on the general public Web, are you taking the required steps to guard them?

Lastly, the Cisco Dwell community is designed to be a protected community for attendees to make use of. However that’s no assure that – elsewhere – the identical SSID couldn’t be used to face up a hostile community.  Shoppers will normally auto-connect once they see a wi-fi community they’ve linked to earlier than.

One dependable mitigation for all of it is a VPN consumer. A correctly configured VPN consumer like Cisco Safe Consumer can help each a full tunnel VPN and “Begin Earlier than Login”.  With this function, the consumer pc connects to the VPN as early as doable.  All site visitors, together with DNS lookups, are despatched over the VPN.  Whereas this doesn’t remove all these dangers, it raises the protection bar considerably.

Take a look at the opposite blogs by my colleagues within the Cisco Dwell Melbourne 2026 SOC.

We’d love to listen to what you assume! Ask a query and keep linked with Cisco Safety on social media.

Cisco Safety Social Media

LinkedInFacebookInstagramX



Source link

Tags: Cisco Breach ProtectionCisco LiveCisco Secure AccessCisco Security CloudCisco TalosCisco User ProtectionCisco XDRControllerCybersecurityDomainNetwork Operations Center NOCSecurity Operations Center SOCSplunkSplunk CloudSplunk Enterprise SecurityThousandEyes
Previous Post

Bike trail approaching finish line

Next Post

53+ Ways to Give Experience Gifts Instead of Stuff This Year (Even Last Minute)

Related Posts

Average portion of cod and chips in UK hits £11.41, report finds
Business

Average portion of cod and chips in UK hits £11.41, report finds

June 29, 2026
July 2026 universal credit, benefits and pensions dates plus cost of living support
Business

July 2026 universal credit, benefits and pensions dates plus cost of living support

June 28, 2026
The Best Way to Fire an Employee (Hint: It’s Not by Email)
Business

The Best Way to Fire an Employee (Hint: It’s Not by Email)

June 27, 2026
Volkswagen ‘to cut 100,000 jobs amid challenging market conditions’
Business

Volkswagen ‘to cut 100,000 jobs amid challenging market conditions’

June 27, 2026
Experts criticise Treasury plans to tax interest on cash in stocks and shares ISAs
Business

Experts criticise Treasury plans to tax interest on cash in stocks and shares ISAs

June 27, 2026
Why Bad Data Is The Silent Killer Of Your Marketing Budget – Young Upstarts
Business

Why Bad Data Is The Silent Killer Of Your Marketing Budget – Young Upstarts

June 26, 2026
Next Post
53+ Ways to Give Experience Gifts Instead of Stuff This Year (Even Last Minute)

53+ Ways to Give Experience Gifts Instead of Stuff This Year (Even Last Minute)

Sheet Pan French Toast With Mixed Berry Sauce

Sheet Pan French Toast With Mixed Berry Sauce

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
This Fish Glows By Stealing Light From Its Prey – Asian Scientist Magazine

This Fish Glows By Stealing Light From Its Prey – Asian Scientist Magazine

April 29, 2026
China’s New Five-Year Plan Prioritizes Robotics. The World Should Pay Attention.

China’s New Five-Year Plan Prioritizes Robotics. The World Should Pay Attention.

March 14, 2026
The 10 Most Beautiful Women in History According to AI

The 10 Most Beautiful Women in History According to AI

October 16, 2025
Satellite imagery shows Philippine construction on two islands in disputed Spratlys

Satellite imagery shows Philippine construction on two islands in disputed Spratlys

May 9, 2026
Summer 2026 Horror Preview: Every Major Horror Movie Coming to Theatres

Summer 2026 Horror Preview: Every Major Horror Movie Coming to Theatres

May 10, 2026
Best ND Filters for Travel Photography: 2026 Pro Picks

Best ND Filters for Travel Photography: 2026 Pro Picks

May 22, 2026
‘9 years, female, white, virgin’: Why Harry Potter, Hello Kitty toys in Europe are being probed for child trafficking

‘9 years, female, white, virgin’: Why Harry Potter, Hello Kitty toys in Europe are being probed for child trafficking

June 29, 2026
I’m a travel expert and this is where you’ll find me on holiday in August

I’m a travel expert and this is where you’ll find me on holiday in August

June 29, 2026
‘Still trying to process it’: Rajasthan-born Jai Moondra leads Ireland’s emotional celebrations after historic series win over India

‘Still trying to process it’: Rajasthan-born Jai Moondra leads Ireland’s emotional celebrations after historic series win over India

June 29, 2026
Rescuers race to find survivors as quake death toll nears 1500

Rescuers race to find survivors as quake death toll nears 1500

June 29, 2026
Trump says work will begin on DC golf course despite judge’s warning

Trump says work will begin on DC golf course despite judge’s warning

June 29, 2026
Mathieu Darche has an Islanders line he won’t cross — and it’s leading to a quiet offseason

Mathieu Darche has an Islanders line he won’t cross — and it’s leading to a quiet offseason

June 28, 2026
World News Prime

Discover the latest world news, insightful analysis, and comprehensive coverage at World News Prime. Stay updated on global events, business, technology, sports, and culture with trusted reporting you can rely on.

CATEGORIES

  • Breaking News
  • Business
  • Entertainment
  • Gaming
  • Health
  • Lifestyle
  • Politics
  • Sports
  • Technology
  • Travel

LATEST UPDATES

  • ‘9 years, female, white, virgin’: Why Harry Potter, Hello Kitty toys in Europe are being probed for child trafficking
  • I’m a travel expert and this is where you’ll find me on holiday in August
  • ‘Still trying to process it’: Rajasthan-born Jai Moondra leads Ireland’s emotional celebrations after historic series win over India
  • About Us
  • Advertise With Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Policy
  • Terms and Conditions
  • Contact Us

© 2025 World News Prime.
World News Prime is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Breaking News
  • Business
  • Politics
  • Health
  • Sports
  • Entertainment
  • Technology
  • Gaming
  • Travel
  • Lifestyle

© 2025 World News Prime.
World News Prime is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In