Christopher Panayi: Extracting Passwords from Microsoft Configuration Manager
A DEF CON 30 talk about vulnerabilities in the system deployment process using Microsoft Endpoint Configuration Manager (MECM) — one of the most widely used tools for managing Windows infrastructure in large organizations.
The presentation shows how misconfigurations in network boot and operating system deployment workflows can expose Active Directory credentials. It explores MECM architecture, the underlying protocols involved, and practical attack techniques, along with a demonstration of a tool that extracts credentials from several MECM deployment scenarios.
The presentation shows how misconfigurations in network boot and operating system deployment workflows can expose Active Directory credentials. It explores MECM architecture, the underlying protocols involved, and practical attack techniques, along with a demonstration of a tool that extracts credentials from several MECM deployment scenarios.