Skip to content

Commit

Permalink
Docs: Improve zerologon explanation
Browse files Browse the repository at this point in the history
  • Loading branch information
mssalvatore committed Jul 22, 2024
1 parent be093c1 commit d7f24e1
Showing 1 changed file with 7 additions and 7 deletions.
14 changes: 7 additions & 7 deletions docs/content/features/exploiters/zerologon.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,8 @@ and account management, is severely affected.

Due to a flaw in the cryptographic authentication scheme of Netlogon, an
attacker can bypass authentication and gain administrator-level privileges to
a machine, including a domain controller, effectively granting the attacker
control over the entire domain.
an unpatched machine, including a domain controller, effectively granting the
attacker control over the entire domain.

Infection Monkey's Zerologon exploiter takes advantage of this vulnerability to
steal credentials from the domain controller, which are then used to propagate
Expand All @@ -47,13 +47,12 @@ https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-1472).

## A note on safety

This exploiter is not safe for production or other sensitive environments. It
is, therefore, **not** enabled by default.

This exploiter is not safe for production or other sensitive environments.
During successful exploitation, the Zerologon exploiter:

* Will temporarily change the target domain controller's password.
* May break the target domain controller's communication with other systems in the network, affecting functionality.
* May break the target domain controller's communication with other systems in
the network, affecting functionality.
* May change the administrator's password.
* Will *attempt* to revert all changes.

Expand Down Expand Up @@ -97,4 +96,5 @@ If all other approaches fail, you can try the tools and steps found
[here](https://github.com/risksense/zerologon).

## See also
- [Zerologon exploiter reference documentation](/reference/exploiters/zerologon)
- [Zerologon exploiter reference
documentation](/reference/exploiters/zerologon)

0 comments on commit d7f24e1

Please sign in to comment.