Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management //


04:38 PM
Larry Loeb
Larry Loeb
Larry Loeb

Preempt Shows How to Sidestep EPA Authentication

Security firm Preempt issued an advisory that showed how to conceptually bypass the Enhanced Protection for Authentication that prevents attackers from performing a relay of NT Lan Manager messages to top-level security sessions.

Security firm Preempt issued an advisory that showed how to conceptually bypass the Enhanced Protection for Authentication (EPA) that prevents attackers from performing a relay of NT Lan Manager (NTLM) messages to top-level security (TLS) sessions. Attackers could use NTLM to enable their own fake sessions. Since a relay attack is the most common one used against the proprietary NTLM, EPA was put there to stop them.

Preempt says that their "bypass allows attackers to modify NTLM messages to generate legitimate channel binding information. This can allow attackers to connect to various web servers using the attacked user's privileges and perform operations such as: read the user's emails (by relaying to Outlook Web Access (OWA) servers) or even connect to cloud resources (by relaying to Active Directory Federation Services (ADFS) servers)."

Also, the Message Integrity Code (MIC) is not tampered with. Instead, it is just cut out. The advisory says, "bypass allows attackers to remove the 'MIC' protection and modify various fields in the NTLM authentication flow, such as signing negotiation."

But wait, one more.

Server Message Block (SMB) Session Signing was to prevent attackers from relaying NTLM authentication messages to establish SMB and other sessions. It's the same relay attack, but the defense tool was adapted for this specific situation.

The researchers went on, "The bypass we discovered enables attackers to relay NTLM authentication requests to any server in the domain, including domain controllers, while establishing a signed session to perform remote code execution. If the relayed authentication is of a privileged user, this means full domain compromise."

Boy Howdy, that's a #fail.

They patched the bypass in the June Patch Tuesday. But just the patching alone is not sufficient to deal with this and other problems.

Preempt says that configuration changes should be done to the network. Because it's NTLM, you know?

Some really relevant network options are:


  • Enforce SMB Signing -- To prevent attackers from launching simpler NTLM relay attacks, turn "SMB Signing" on throughout the network.



  • Block NTLMv1 -- Since NTLMv1 is considered significantly less secure, it is recommended to completely block it by setting the appropriate GPO. Why make it worse than it has to be?



  • Enforce LDAP/S Signing -- To prevent NTLM relay in Lightweight Directory Access Protocol (LDAP), enforce LDAP signing and LDAPS channel binding on domain controllers.



  • Enforce EPA -- To prevent NTLM relay on web servers, harden all web servers (OWA, ADFS) to accept only requests with EPA. Reduce NTLM usage - Even with a fully secure configuration and fully patched servers NTLM still poses a significantly greater risk to most analysts than Kerberos. Preempt recommends that you remove NTLM anywhere it is not needed.


— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Attackers Leave Stolen Credentials Searchable on Google
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2021
How to Better Secure Your Microsoft 365 Environment
Kelly Sheridan, Staff Editor, Dark Reading,  1/25/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-01-25
The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forged. The problem has been fixed in commit f828dc6 by making use of Medi...
PUBLISHED: 2021-01-25
ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go Module. In ORAS from version 0.4.0 and before version 0.9.0, there is a "zip-slip" vulnerability. The directory support feature allows the ...
PUBLISHED: 2021-01-25
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML ...
PUBLISHED: 2021-01-25
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting