Who are you? How do I verify who you are, and once I do, what should I allow you to do, and how do I ensure
- Static passwords: A password that doesnt' change over time.
- Dynamic Passowrds: Passwords taht are changed on regular intervals e.g. LAPS
- One-time passwords: A variant of dynamic passwords that's changed every time it is used.
- Passphrases: a 'longer' password e.g. natural language sentences "I have a plan. Attack!"
- Salts: A random value added to a password prior to hashing, which will encrypt differently.
- Dictionary: A word list, e.g. rockyou.txt
- Hybrid Attack: appends, prepends or changes characters in words from a dictionary before hashing
- Brute Force: calculates hash outputs for every possible password
- Rainbow Tables: a database that contains the precomputed hashed output for most or all passwords
- Synchronous dynamic password token: Generates passwords at fixed time intervals. Entered along with a passphrase or password.
- Asynchronoous dynamic password token: Generates onetime passwords after the user enters a PIN in the token device.
- False Acceptance Rate (FAR): unauthorized subjects are accepted as valid
- False Rejection Rate (FRR): authorized subjects are rejected.
- Crossover Error Rate (CER): the point where FAR and FRR are equal. This describes the overall accuracy of the system
- Rule-Based: Much broader scenarios than individual subjects accessing objects e.g. a Firewall – RBAC: Role Based Access Control. Defined rules or restrictions for accesing objects in a system
- DAC: Users have direct control over all programs and files
- MAC: Opposite of DAC. Using a policy or Hardware/Software component to restrict access
- Federated Identity Management: applies SSO at a wider scale ranging from cross-organiztional to Internet scale.
- SAML: An XML based framework for exchanging security information
- LDAP: A common open protocol for interfacing and querying directory service informaiton provided by network operating systems.
- Kerberos: Authentication service used to support SSO using symmetric encryption providing mutual authentication of clients and servers
- Principal: Client (user) or service
- Realm: A logical Kerberos network
- ticket: Data authenticating a principal's identity
- Credentials: A ticket and service key
- KDC: Key Distribution Center, authenticates principles
- TGS: Ticket Granting Service
- TGT: Ticket Granting Ticket
- C/S: Client Server, regarding communications between the two
- It refers to five elements: Identification, authentication, authorization, auditing, and accounting.
- Authentication: The process of verifyhing or testing the identity claimed by a subject is valid.
- Authorization: The process ensuring the subject accessing the object has the necessary rights and privileges.
- Accounting: The process of holding someone responsible for something. Accoutability is possible if a subject's identity and actions can be tracked and verified.
- RADIUS: Remote Authentication Dial In User Servcie. An AAA system comuunicating over UDP (ports 1812, 1813).
- Diameter: A successor to RADIUS
- TACACS/TACACS+: Terminal access controller access control system. A centralized access control system requiring users to sen4d and ID and static password for authentication. TACACS+ allows for two-factor strong authentication. Uses UDP (port 49). TACACS+ uses TCP (port 49)
- PAP/CHAP: PAP (Password Authentication Protocol) is insecure as passwords are sent in clear text. CHAP (Challenge Handshake Authentication Protocol). Provides protection against playback attacks.
- Back to the YouTube Video
- Bypassing Biometric Controls
- Kerberos Deep Dive
- Kerberos steps explained better
- Password Lists
- TryhackMe - Attacking Active Directory
- Darnet Diaries Episode 33 - Rockyou
- BloodHound
- Inside Cloud and Security - Domain 5
- Rule Based vs Role Based Access Control
- Plan for Kerberos Authentication
- Microsoft LAPS

