Skip to content

Conversation

@LazyTitan33
Copy link

With a different way to authenticate, it is possible to detect LDAP codes and as such be able to detect situations where the password is expired but the user is still enabled, situations where the password must change (user enabled but never logged on) and now can also see when accounts get locked out.

image

I was password spraying during an engagement and missed a DA account with an expired password because it wasn't flagged so I implemented this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant