
when you change your password, it's already stolen
Keywords
Summary
159 words
Critical Evaluation
Value of the Information & Strength of the Argument
The video provides valuable information by demonstrating a real, working attack technique that is often overlooked. The argumentation is solid, as it builds on documented research and shows the attack in a practical environment. The step-by-step code walkthrough is clear and allows viewers to understand the inner workings. The video also contextualizes the technique within the MITRE ATT&CK framework, adding credibility. However, the video does not discuss mitigations in depth, which could be a limitation for defensive purposes.
Scientific Rigor, Source Quality, Title Accuracy
The video cites the original blog post by Rob Fuller and the MITRE ATT&CK technique page, which are authoritative sources. The title accurately reflects the content. The video is a tutorial, and the sources are used appropriately. The sponsor segment is clearly separated and does not affect the technical content. The video does not provide a detailed analysis of the technique’s prevalence or detection, but it is honest about the age of the technique.
167 words
Title / Content Match
The title accurately reflects the content: it demonstrates how passwords can be stolen at the moment of change.
Quality & Reliability
8/10
The video is a practical tutorial demonstrating a well-documented Windows password filter attack. The technique is based on a 2013 blog post by Rob Fuller and is referenced to MITRE ATT&CK. The demonstration is clear and reproducible, and the code is simple. However, the video includes a sponsor segment and the technique is old, though still relevant.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction to password filters and the attack concept.
- Explanation of password filter functions and how they are called.
- Sponsor segment for Specops Software.
- Setting up the Visual Studio project and writing the DLL code.
- Implementing the PasswordChangeNotify function to log passwords.
- Compiling the DLL and preparing to install it.
- Copying the DLL to System32 and modifying the registry.
- Rebooting and demonstrating the password capture.
- Discussion of the technique's applicability on domain controllers.
- Conclusion and call to action.
Cited Sources
- Stealing passwords every time they change — Original blog post by Rob Fuller describing the password filter attack.
- MITRE ATT&CK Technique T1556.002 — Documentation of the technique in the MITRE ATT&CK framework.
- Carnal0wnage blog post — Alternate link to the blog post, as mentioned in the video.
Concurring Sources
- MITRE ATT&CK Technique T1556.002 — Confirms the technique is recognized in the industry.
External References
Contribution & Novelties
The video provides a clear, hands-on demonstration of a relatively obscure but effective credential theft technique. It updates the 2013 technique to modern Windows 11, showing that it still works. The video also highlights the importance of understanding Windows internals for both offensive and defensive security.
Pour aller plus loin :
- MITRE ATT&CK T1556.002 — Official documentation of the technique.
- Windows Password Filters documentation — Microsoft’s documentation on password filters.
- Local Security Authority (LSA) Architecture — Overview of LSA and its role in authentication.
84 words
Radar Profile
The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a well-balanced and accessible tutorial.
💬 No comments were provided for analysis.