Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Let This Tale From The Crypt Of Pentesting Be A Warning To All
Articles

Let This Tale From The Crypt Of Pentesting Be A Warning To All

ISBuzz TeamBy ISBuzz TeamMarch 17, 2014Updated:September 5, 20196 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
weidman
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

With official support for Windows XP set to end on April 8th, what are the biggest security fears and what should users do about it?

Windows XP is by definition an easier target for exploit developers than more modern versions of Windows. While Data Execution Prevention (DEP) was introduced in Windows XP SP2 (though its not on for most programs by default on Desktop OSes even on Windows 7), Address Space Layout Randomization, a feature that makes it more difficult for attackers to build reliable exploits was not introduced until Windows Vista. Additionally, by default Windows XP stores passwords hashed using a legacy, insecure algorithm, LM hash. If you have not been keeping your Windows XP systems patched, they may already be vulnerable to full compromise from the network with known issues in easy to use tools such as Metasploit. For enterprises that are not patching regularly and providing security oversight, the end of support for Windows XP will make no difference. These systems are vulnerable to attack today and they will vulnerable to attack tomorrow. On the other hand, if you are keeping your Windows XP installs up to date on patching as well as providing oversight for patching and security for third party programs installed such as FTP servers or client side programs such as browsers or PDF readers, your Windows XP systems may be as secure against known vulnerabilities as Windows 7 or Windows 8 systems. That’s all about to change though. With Microsoft ending support for Windows XP, any vulnerabilities that are discovered in the future will not be patched by the vendor, leaving all installs of Windows XP perpetually vulnerable.
[wp_ad_camp_4]
How big a deal is end of support for XP really going to be for enterprises that still have XP deployed but are keeping up to date with known security issues? It’s hard to say at this point. On the one hand, talented security researchers have discovered many exploitable security issues for XP during its tenure. A lot of bugs have been patched by Microsoft. It is not going to be trivial to get command execution access to Windows XP from the network. There will likely be better success with client side attacks, requiring an active user using the vulnerable system. But as seen at the recent Pwn2Own hacking contest where the latest versions of Flash, Safari, Firefox, etc. all fell victim to new exploits from researchers, with enough time and effort, it is possible to find exploitable bugs on nearly any target, even ones that use the latest and greatest security mitigations. Look at the iPhone for example. Each time an operating system update is released, Apple is throwing down the gauntlet that this time there will be no jailbreak; this version of the iPhone operating system is secure. And every time, give it a few weeks to a few months, a jailbreak is developed.

With XP losing support, it suddenly becomes a more lucrative target for bug hunters. Any exploitable bugs that are found will remain exploitable since no patch will be released. The only way to make these bugs less valuable, and thus cause bug hunters to turn their attention to another target, is decommissioning all Windows XP systems for later, more secure versions of Windows. If you use later versions of Windows in your enterprise it may seem foreign to you that anyone could still be using XP, but in my pentesting career I’m still running into XP and even Windows 2000. If you spend any time in airports you may see a Windows XP screensaver or two on by mistake as you look at flight listings and other informational screens throughout the environment. Computer labs in enterprises or universities are another culprit I see a lot.

I once worked with a client who had recently rebuilt their Windows infrastructure using Windows 2008 and Windows 7. Client side exploitation and social engineering were not in scope at this phase of the test, so I was having a bit of trouble getting access to the domain. Even password guessing wasn’t going too well for me. But then I found it, an old Windows 2000 box that used to be the domain controller. And like most Windows 2000 systems you find still running, it was trivial to get SYSTEM level access from the network. Technically I now had domain admin, albeit on a domain controller with no client machines. So my pentest was a success, right? But I hold myself to a higher standard, requiring access to sensitive data, and domain administrator privileges on all domains in the enterprise, etc. before I am satisfied with the test. This Windows 2000 box had nothing interesting on it at all. No email accounts, no sensitive data, no domain clients. However, there was one little problem. Being the domain controller this system stored the domain password hashes locally. And if you recall Windows 2000, like Windows XP stores both the legacy LM hash and the newer, more secure NTLM hash of Windows passwords. LM hash is completely reversible, regardless of how strong the password is. The domain admin password for the Windows 2000 domain was 9 characters long, had characters from multiple complexity classes, and was not based on a dictionary word, but since I had the LM hash I was able to brute force it in less than an hour. Can you guess what the domain admin password on the client’s new Windows 2008 domain was? You guessed it, the exact same password, giving me domain admin access to all those patched and hardened Windows 7 clients with email accounts, customer’s medical data, etc in plain sight. My client had done a lot right. They had updated their infrastructure to modern versions of Windows, no longer using the unsupported legacy system as a domain controller. They were using strong passwords (though I recommended to them in the future that they should not reuse passwords across domains and should change all passwords on a regular cycle.) Their main problem was that they had left the Windows 2000 system running even though it no longer served a business function. So let this tale from the crypt of pentesting be a warning to all.

Georgia Weidman | CEO, Bulb Security LLC | @georgiaweidman

To find out more about our panel members visit the biographies page.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}