<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5043195767541326568</id><updated>2026-04-11T00:41:53.611-07:00</updated><category term="security"/><category term="SSL"/><category term="Cryptography"/><category term="IT Culture"/><category term="LDAP"/><category term="PKI"/><category term="windows"/><category term="IT Staffing"/><category term="Investing"/><category term="Oracle"/><category term="TLS"/><category term="active directory"/><category term="certificates"/><category term="&quot;Advanced Persistent Protection"/><category term="AD"/><category term="APT"/><category term="Advance Persistent Controls"/><category term="Advanced Persistent Control Suite"/><category term="Awesome"/><category term="BigIP"/><category term="CAG"/><category term="CSV"/><category term="Citrix access gateway enterprise"/><category term="CredSSP"/><category term="F5"/><category term="HSM"/><category term="HTTP"/><category term="HTTPS"/><category term="IT"/><category term="Kerberos"/><category term="LDAPS"/><category term="LSASS"/><category term="Load balance"/><category term="NLA"/><category term="PowerShell"/><category term="Root DSE"/><category term="TCP/IP"/><category term="Tools"/><category term="Two-factor authentication"/><category term="VB Script"/><category term="VBS"/><category term="Web servers"/><category term="XLS"/><category term="XLSX"/><category term="active directory;gmsa"/><category term="active directory;gmsa;adws;ldap"/><category term="active directory;gmsa;adws;ldap;powershell"/><category term="advanced persistent threat"/><category term="analysis"/><category term="attacks"/><category term="bloodhound"/><category term="butter"/><category term="captcha"/><category term="controls"/><category term="convert"/><category term="csharp"/><category term="email"/><category term="excel"/><category term="finances"/><category term="free"/><category term="hosting"/><category term="index funds"/><category term="key management"/><category term="keys"/><category term="money"/><category term="netscaler"/><category term="openSSL"/><category term="pass the hash"/><category term="pentest"/><category term="portproxy"/><category term="red team"/><category term="requirements"/><category term="saving money"/><category term="which"/><category term="windows XP"/><title type='text'>Mark R. Gamache&#39;s Random Blog</title><subtitle type='html'>Here&#39;s random stuff related to what I am working on or interested in during my work day or in my personal life.  I&#39;m a nerd.  The content will be nerdy.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>46</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-4065454308785808113</id><published>2020-07-15T18:20:00.000-07:00</published><updated>2020-07-15T18:27:11.210-07:00</updated><title type='text'>Exploiting AD gpLink for Good or Evil</title><summary type="text">




GPOwn

&lt;!--
 /* Font Definitions */
 @font-face
 {font-family:Wingdings;
 panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
 {font-family:&quot;Cambria Math&quot;;
 panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
 {font-family:Calibri;
 panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
 {font-family:&quot;Calibri Light&quot;;
 panose-1:2 15 3 2 2 2 4 3 2 4;}
@font-face
 {font-family:Consolas;
 panose-1:2 11 6 9 2 2 4 3 2 4;}
 /* </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/4065454308785808113/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/4065454308785808113' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/4065454308785808113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/4065454308785808113'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2020/07/exploiting-ad-gplink-for-good-or-evil.html' title='Exploiting AD gpLink for Good or Evil'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9szhT75omwsj4lyRnWrOLXjP1Qs-h6mx7AOFXonKuch8I1I6-IatN7Qnx83KfbMVHgATEesYw_dfqemLuNz2dNZ3yiMjCkqoujIBI5itS57rdy5xHBqM_c-8zpOCmA0SS4gDW1lagTi0/s72-c/ExploitinggpLink_image001.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-2240251647124971625</id><published>2018-03-28T20:42:00.000-07:00</published><updated>2018-03-28T20:45:13.838-07:00</updated><title type='text'>If I Can&#39;t Reach Active Directory, it&#39;s Down</title><summary type="text">Unless it&#39;s not.

I recently had a customer tell me that my AD servers were broken. They were unable to set SPNs via Setspn.

They were able to run AD queries and were able to do other &quot;AD Stuff&quot;. As always, I demanded a packet capture.

In very short order, the issue was clear. Setspn, for reasons I cannot guess, uses RPCs to the domain controller to set SPNs. I have not clue why it doesn&#39;t just</summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/2240251647124971625/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/2240251647124971625' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2240251647124971625'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2240251647124971625'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2018/03/if-i-cant-reach-active-directory-its.html' title='If I Can&#39;t Reach Active Directory, it&#39;s Down'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzdpljGMGxdd1NGPvPi_2jUIdZhT6HZS2QdD3s3tDjlERrQYJ041xBnVeetBt0OhFyGHQyGrEPtNdaNb4LTsuC_fEMAhcTP1HdeRWjlzs6_LMMJvqYdt2e60p_i_BaUnWOr8tuFoHBacI/s72-c/Capture.GIF" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-1493675287144234136</id><published>2018-03-28T20:05:00.000-07:00</published><updated>2018-03-28T20:05:25.520-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="AD"/><category scheme="http://www.blogger.com/atom/ns#" term="Kerberos"/><category scheme="http://www.blogger.com/atom/ns#" term="portproxy"/><title type='text'>Living off the land with Kerberos and netsh interface portproxy</title><summary type="text">
Have you ever been in the situation where you need to do
some remote PowerShell on a machine, but you can’t find a layer 3 path to the
server? 



Did you find out that you could get remote PowerShell on the
machine next to it, but you don’t want to pass your credentials to that
machine, to double hop?&amp;nbsp; You know, ‘cause
you aren’t insane…



Did you ever say, why can’t I use that machine </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/1493675287144234136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/1493675287144234136' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/1493675287144234136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/1493675287144234136'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2018/03/living-off-land-with-kerberos-and-netsh.html' title='Living off the land with Kerberos and netsh interface portproxy'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlhIPLgTDVRKS90F4tVfjTecEb2yYVkXgpROmKup9dnWKXcqaDo-TgaEfvt1t-6eo-du82Zs4ozuDAxKxaTwW-zsIf7p-6xlxMPkYRdduDvoe8jCawcrZ6oPpck7dMN0OBCj_MQUAA1fg/s72-c/Drawing1.gif" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-1761859479385341788</id><published>2017-08-28T15:11:00.000-07:00</published><updated>2017-08-28T15:11:53.864-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="index funds"/><category scheme="http://www.blogger.com/atom/ns#" term="Investing"/><title type='text'>Keep an Eye on Your Index Fund Dollars.  You May be Surprised. </title><summary type="text">



Keep and eye on your Index fund money

&lt;!--
 /* Font Definitions */
 @font-face
 {font-family:&quot;Cambria Math&quot;;
 panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
 {font-family:Calibri;
 panose-1:2 15 5 2 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
 {margin-top:0in;
 margin-right:0in;
 margin-bottom:8.0pt;
 margin-left:0in;
 line-height:107%;
 font-size:11.0pt;
 </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/1761859479385341788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/1761859479385341788' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/1761859479385341788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/1761859479385341788'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2017/08/keep-eye-on-your-index-fund-dollars-you.html' title='Keep an Eye on Your Index Fund Dollars.  You May be Surprised. '/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-1528825538462078973</id><published>2017-08-25T11:22:00.000-07:00</published><updated>2017-09-29T08:56:06.600-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="active directory"/><category scheme="http://www.blogger.com/atom/ns#" term="attacks"/><category scheme="http://www.blogger.com/atom/ns#" term="bloodhound"/><category scheme="http://www.blogger.com/atom/ns#" term="pentest"/><category scheme="http://www.blogger.com/atom/ns#" term="red team"/><title type='text'>Detecting Attackers in a Windows Active Directory Network</title><summary type="text">


I Smell Attackers

&lt;!--
 /* Font Definitions */
 @font-face
 {font-family:&quot;Cambria Math&quot;;
 panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
 {font-family:&quot;Calibri Light&quot;;
 panose-1:2 15 3 2 2 2 4 3 2 4;}
@font-face
 {font-family:Calibri;
 panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
 {font-family:Consolas;
 panose-1:2 11 6 9 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/1528825538462078973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/1528825538462078973' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/1528825538462078973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/1528825538462078973'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2017/08/detecting-attackers-in-windows-active.html' title='Detecting Attackers in a Windows Active Directory Network'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-3576707434476677322</id><published>2017-08-20T11:17:00.000-07:00</published><updated>2017-08-20T11:17:19.316-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="finances"/><category scheme="http://www.blogger.com/atom/ns#" term="Investing"/><category scheme="http://www.blogger.com/atom/ns#" term="money"/><title type='text'>Keep an Eye on Those Bond Investment Fees </title><summary type="text">While re-balancing&amp;nbsp;my portfolio stock/bond/cash ratios, I discovered something I had
not seen before…

While I talk about my Fidelity account, it is almost certain that this issue will be found with most brokerages.&amp;nbsp;

If
you use the Brokerage link option to manage your 401K investments, and if you
have other Fidelity investment accounts, it is worth taking a look at your
“core position”</summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/3576707434476677322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/3576707434476677322' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/3576707434476677322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/3576707434476677322'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2017/08/keep-eye-on-those-bond-investment-fees.html' title='Keep an Eye on Those Bond Investment Fees '/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilfCGuLQnL5rz7xRu8MHvcdIyK9SZQqg7Wy8XMP1j46OGAgoMpJR56PsOeXX1wi3agZmEkzYkD8n-TNEs5EaCIlBYur16FU0MLWpZ3eSFAntKkNCxrm8gUCMxjm5GrgvPR2wyeD-Lch8I/s72-c/fees.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-3583586514068603934</id><published>2017-08-07T13:37:00.001-07:00</published><updated>2017-08-08T16:29:33.690-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="active directory"/><category scheme="http://www.blogger.com/atom/ns#" term="PKI"/><category scheme="http://www.blogger.com/atom/ns#" term="PowerShell"/><title type='text'>Copying the NTAuth Enterprise store certificates from one Forest to another</title><summary type="text">The enterprise NTAuth store is a key Active Directory configuration item. It is key to allowing user to login with smartcards. When using PKI cross forest, we usually&amp;nbsp;use the PKISync.ps1 script to lihnk the two forests PKI configurations. This script is designed to allow cross forest certificate enrollment, wich it does well. &amp;nbsp;It does not cover the NTAuth config for smartcards. &amp;nbsp;</summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/3583586514068603934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/3583586514068603934' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/3583586514068603934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/3583586514068603934'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2017/08/copying-ntauth-enterprise-store.html' title='Copying the NTAuth Enterprise store certificates from one Forest to another'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-4069293476620568104</id><published>2017-03-24T18:56:00.000-07:00</published><updated>2017-03-24T18:56:17.816-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="saving money"/><title type='text'>I Just Saved $121!!</title><summary type="text">I&#39;m not one to pimp products unless they are really good and I understand them, but today is an exception. 

I have NO IDEA how GoodRX works, but I do know it saved me $121.11 on a single prescription. &amp;nbsp;Usually, when you install an app that get&#39;s you something for free, you are the commodity. &amp;nbsp;Most apps want all sorts of crazy access to your phone. &amp;nbsp;GoodRX wanted pretty basic </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/4069293476620568104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/4069293476620568104' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/4069293476620568104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/4069293476620568104'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2017/03/i-just-saved-121.html' title='I Just Saved $121!!'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-1185697936552616157</id><published>2017-03-16T12:07:00.000-07:00</published><updated>2017-09-29T08:57:13.803-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CredSSP"/><category scheme="http://www.blogger.com/atom/ns#" term="NLA"/><category scheme="http://www.blogger.com/atom/ns#" term="windows"/><title type='text'>The Tyranny of Network Level Authentication and CredSSP</title><summary type="text">


The Tyranny of Network Level Authentication and CredSSP

&lt;!--
 /* Font Definitions */
 @font-face
 {font-family:&quot;Cambria Math&quot;;
 panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
 {font-family:Calibri;
 panose-1:2 15 5 2 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
 {margin-top:0in;
 margin-right:0in;
 margin-bottom:8.0pt;
 margin-left:0in;
 line-height:105%;
 </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/1185697936552616157/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/1185697936552616157' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/1185697936552616157'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/1185697936552616157'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2017/03/the-tyranny-of-network-level.html' title='The Tyranny of Network Level Authentication and CredSSP'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-2025844680801816991</id><published>2017-02-10T18:12:00.000-08:00</published><updated>2017-02-10T18:12:45.542-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="active directory;gmsa;adws;ldap;powershell"/><title type='text'>PowerShell Module for Reading Group Managed Service Account Passwords</title><summary type="text">I recently covered the topic of Active Directory Group Managed Service Accounts. They are the new hotness from Microsoft. &amp;nbsp;I also offed up some code snippets for interacting with them.


Now I offer up a PowersShell module that also exposes .NET classes and methods for reading gMSA passwords.&amp;nbsp;



This module has a couple of great uses. &amp;nbsp;First of all, not all services and </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/2025844680801816991/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/2025844680801816991' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2025844680801816991'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2025844680801816991'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2017/02/powershell-module-for-reading-group.html' title='PowerShell Module for Reading Group Managed Service Account Passwords'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-2815801968707903511</id><published>2016-12-30T10:38:00.001-08:00</published><updated>2017-09-29T08:57:48.031-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="active directory;gmsa"/><title type='text'>gMSAs are a Little Bit Weird</title><summary type="text">



&lt;!--
 /* Font Definitions */
 @font-face
 {font-family:Wingdings;
 panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
 {font-family:&quot;Cambria Math&quot;;
 panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
 {font-family:Calibri;
 panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
 {font-family:Consolas;
 panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
 {font-family:&quot;Segoe UI&quot;;
 panose-1:2 11 5 2 4 2 4 2 2 3;}
 /* Style </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/2815801968707903511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/2815801968707903511' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2815801968707903511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2815801968707903511'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2016/12/gmsas-are-little-bit-weird.html' title='gMSAs are a Little Bit Weird'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-689239745880213904</id><published>2016-12-28T15:14:00.002-08:00</published><updated>2017-09-29T08:58:28.140-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="active directory;gmsa;adws;ldap"/><title type='text'>Any sufficiently advanced Active Directory Web Service is indistinguishable from magic</title><summary type="text">




&lt;!--
 /* Font Definitions */
 @font-face
 {font-family:&quot;Cambria Math&quot;;
 panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
 {font-family:Calibri;
 panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
 {font-family:&quot;Calibri Light&quot;;
 panose-1:2 15 3 2 2 2 4 3 2 4;}
@font-face
 {font-family:Consolas;
 panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
 {font-family:Verdana;
 panose-1:2 11 6 4 3 5 4 4 2 4;}
 /* Style </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/689239745880213904/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/689239745880213904' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/689239745880213904'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/689239745880213904'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2016/12/any-sufficiently-advanced-active.html' title='Any sufficiently advanced Active Directory Web Service is indistinguishable from magic'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-9211442449844077615</id><published>2016-12-06T19:35:00.001-08:00</published><updated>2016-12-06T19:35:38.960-08:00</updated><title type='text'>The Strange Case of John Legere&#39;s Alien Abduction</title><summary type="text">
From the first time I talked to John Legere face to face, I felt
there was an &quot;other worldly&quot; quality to him. He seemed to radiate
some sort of power.



Based on
T-Mobile&#39;s&amp;nbsp;quarter
over quarter performance&amp;nbsp;since
his taking the reins, I think it is pretty clear what is going on...




I suspect that
John Legere was abducted by aliens and subjected to some sort of enhancements.&amp;nbsp;


</summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/9211442449844077615/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/9211442449844077615' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/9211442449844077615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/9211442449844077615'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2016/12/the-strange-case-of-john-legeres-alien.html' title='The Strange Case of John Legere&#39;s Alien Abduction'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://img.youtube.com/vi/RZETOX8KeZQ/default.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-7237051600845302447</id><published>2016-11-09T07:53:00.002-08:00</published><updated>2016-11-09T07:53:52.053-08:00</updated><title type='text'>Just to Clarify </title><summary type="text">Ghee is butter</summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/7237051600845302447/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/7237051600845302447' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/7237051600845302447'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/7237051600845302447'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2016/11/just-to-clarify.html' title='Just to Clarify '/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-5474683424842336474</id><published>2014-05-15T13:34:00.000-07:00</published><updated>2014-05-15T13:50:43.316-07:00</updated><title type='text'>Thank You Satya Nadella, for Saving the Internet... for a while</title><summary type="text">A while back, I asked if&amp;nbsp;Satya Nadella was going to reverse MSs decision to stop publishing security patches for XP, for free. &amp;nbsp;I didn&#39;t get a call or email from Mr.&amp;nbsp;Nadella and MS did not change their overall plan.

That said, MS decided to release the big Internet Explorer patch and include XP. This is a particularly big bug and would be devastating to the web, if left unpatched.</summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/5474683424842336474/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/5474683424842336474' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/5474683424842336474'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/5474683424842336474'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2014/05/thank-you-satya-nadella-for-saving.html' title='Thank You Satya Nadella, for Saving the Internet... for a while'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-3158365132921619869</id><published>2014-02-21T14:25:00.001-08:00</published><updated>2014-02-21T14:55:17.348-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT Culture"/><category scheme="http://www.blogger.com/atom/ns#" term="IT Staffing"/><title type='text'>Tech Job Postings are Funny! Post 1  Amazon.com</title><summary type="text">I get a lot of recruiters emailing me and I get job postings in my RSS feeds. &amp;nbsp;Many of these postings are unintentionally funny, some are downright embarrassing, and some just leak a lot of information about a company. 

I&#39;ve decided to start posting some of these with commentary. &amp;nbsp;The one that finally made this decision for me is from Amazon.com&amp;nbsp;. A copy can be found here. I&#39;ve </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/3158365132921619869/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/3158365132921619869' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/3158365132921619869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/3158365132921619869'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2014/02/tech-job-postings-are-funny-post-1.html' title='Tech Job Postings are Funny! Post 1  Amazon.com'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-3717427953982175974</id><published>2014-02-09T15:28:00.000-08:00</published><updated>2014-02-10T09:32:51.265-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="windows XP"/><title type='text'>Will Satya Nadella Save the Internet on April 8th 2014?</title><summary type="text">













If you have worked for Microsoft, or any huge company, this
will be no surprise; Microsoft has many groups working against each other or at
least spending dollars in one department that could save or make millions in
another. It’s not easy to align everything in a large company, especially when
it has been run by the worst
CEO in America for so long. Microsoft is regularly in the </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/3717427953982175974/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/3717427953982175974' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/3717427953982175974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/3717427953982175974'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2014/02/will-satya-nadella-save-internet-on.html' title='Will Satya Nadella Save the Internet on April 8th 2014?'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-2256624748352319047</id><published>2014-01-11T12:44:00.002-08:00</published><updated>2016-12-07T12:10:06.784-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="email"/><category scheme="http://www.blogger.com/atom/ns#" term="hosting"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><title type='text'>Godaddy Asks People NOT TO USE ITS HOSTED EMAIL and May Not Even Use It Themselves</title><summary type="text">
















Disclaimer,
Godaddy made me angry with a billing issue. &amp;nbsp;This is what caused me to
look into the value I get from them.&amp;nbsp; While my language may be angry and
inflammatory, the facts are not disputable.&amp;nbsp; I have informed them about
their messed up SMTP TLS, but have not heard back.

Try to send
a secure mail to Godaddy hosted addresses and they will return this message</summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/2256624748352319047/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/2256624748352319047' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2256624748352319047'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2256624748352319047'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2014/01/godaddy-asks-people-not-to-use-its.html' title='Godaddy Asks People NOT TO USE ITS HOSTED EMAIL and May Not Even Use It Themselves'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-5851637835786770286</id><published>2013-05-20T22:27:00.000-07:00</published><updated>2016-12-18T09:40:31.570-08:00</updated><title type='text'>Demystifying Certificate Requirements in Mutual TLS</title><summary type="text">











Understanding Certificates and SSL/TLS long ago became an IT
fundamental. 

Somehow, the industry seems to have not noticed.  In my
quest to take fewer calls on this stuff, here is my attempt to help demystify
all the certificates involved in Client SSL/Mutual TLS.  I seem to be spending
2+ hours a day on the phone talking web and server admins through this stuff.

The reason I am </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/5851637835786770286/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/5851637835786770286' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/5851637835786770286'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/5851637835786770286'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2013/05/demystifying-certificate-requirements.html' title='Demystifying Certificate Requirements in Mutual TLS'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-4964901513723275235</id><published>2013-03-29T18:24:00.000-07:00</published><updated>2014-02-10T09:31:24.077-08:00</updated><title type='text'>Hello IT Person, Welcome to the Security Organization</title><summary type="text">










This is a post that is long overdue.   The IT industry went
through a revolution and most people in IT missed it and are still missing it. 


If you are in any form of IT related job, you are in the
information security field.

You may say, “No, I’m just an IT Project Manager (analyst,
whatever), security is another team”.  You are wrong and your career is heading
towards a cliff. 

It</summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/4964901513723275235/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/4964901513723275235' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/4964901513723275235'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/4964901513723275235'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2013/03/hello-it-person-welcome-to-security.html' title='Hello IT Person, Welcome to the Security Organization'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-7485970339411486511</id><published>2013-01-15T14:32:00.000-08:00</published><updated>2014-07-07T14:07:49.196-07:00</updated><title type='text'>NTLM hasn’t been relevant for like 12 years... and other lies.</title><summary type="text">











A surprising number of foolish Slashdotters have pointed out that
my latest work, breaking
the NTLM and LM handshakes and phishing for users’ NT hashes, is totally
irrelevant and has been for 12ish years. &amp;nbsp;

As a fan of debate, I’ll start with points that are interesting
but have no real bearing on the topic.

Slashdotters are
     clearly not
     qualified to make this </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/7485970339411486511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/7485970339411486511' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/7485970339411486511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/7485970339411486511'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2013/01/ntlm-hasnt-been-relevant-for-like-12.html' title='NTLM hasn’t been relevant for like 12 years... and other lies.'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-8193389423091902167</id><published>2013-01-08T10:00:00.000-08:00</published><updated>2017-10-18T19:38:53.122-07:00</updated><title type='text'>NTLM Challenge Response is 100% Broken (Yes, this is still relevant)</title><summary type="text">


NTLM Challenge Response is 100% Broken (Yes, this is still relevant)

&lt;!--
 /* Font Definitions */
 @font-face
 {font-family:&quot;Cambria Math&quot;;
 panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
 {font-family:Calibri;
 panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
 {font-family:Consolas;
 panose-1:2 11 6 9 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
 {margin-top:0in;
 </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/8193389423091902167/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/8193389423091902167' title='15 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/8193389423091902167'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/8193389423091902167'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2013/01/ntlm-challenge-response-is-100-broken.html' title='NTLM Challenge Response is 100% Broken (Yes, this is still relevant)'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>15</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-2551777593935915642</id><published>2013-01-04T21:55:00.001-08:00</published><updated>2014-02-10T09:45:24.739-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cryptography"/><category scheme="http://www.blogger.com/atom/ns#" term="pass the hash"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="windows"/><title type='text'>Rehashing Pass the Hash</title><summary type="text">











The first question one might ask is, “Really…&amp;nbsp; Why are
you writing about this old news now?”&amp;nbsp; The answer is simple; even with the
release of Window 8 and Server 2012, Pass the Hash (PTH) attacks are still
incredibly simple and effective.&amp;nbsp; While from an academic standpoint
passing the hash is simple to understand, it is a bit more complex from an
attacker or defender’s </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/2551777593935915642/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/2551777593935915642' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2551777593935915642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2551777593935915642'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2013/01/rehashing-pass-hash.html' title='Rehashing Pass the Hash'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-6682651066453188756</id><published>2012-09-16T12:46:00.000-07:00</published><updated>2013-01-12T09:39:19.291-08:00</updated><title type='text'>Microsoft, STOP WITH THE SOCIAL!</title><summary type="text">Researching some&amp;nbsp;nuanced&amp;nbsp;Microsoft systems information has caused me to put this string in my always&amp;nbsp;open&amp;nbsp;cut and pasted text file:&amp;nbsp;site:microsoft.com -site:social.technet.microsoft.com -site:social.msdn.microsoft.com

I have searched for hundreds of bits of MS info and looked for hundreds of MS&amp;nbsp;solutions&amp;nbsp;to issues via Bing and Google. &amp;nbsp;I HAVE NEVER FOUND </summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/6682651066453188756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/6682651066453188756' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/6682651066453188756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/6682651066453188756'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2012/11/microsoft-stop-with-social.html' title='Microsoft, STOP WITH THE SOCIAL!'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5043195767541326568.post-2916609761133859419</id><published>2012-03-15T19:56:00.000-07:00</published><updated>2014-07-21T08:25:45.785-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="HTTPS"/><category scheme="http://www.blogger.com/atom/ns#" term="PKI"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="SSL"/><category scheme="http://www.blogger.com/atom/ns#" term="TLS"/><category scheme="http://www.blogger.com/atom/ns#" term="Web servers"/><title type='text'>Proper PKI Configuration for SSL/TLS Servers</title><summary type="text">





&lt;!--
 /* Font Definitions */
 @font-face
 {font-family:Wingdings;
 panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
 {font-family:&quot;Cambria Math&quot;;
 panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
 {font-family:Tahoma;
 panose-1:2 11 6 4 3 5 4 4 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
 {margin:0in;
 margin-bottom:.0001pt;
 font-size:12.0pt;
 font-family:&quot;Times New Roman&quot;,&quot;</summary><link rel='replies' type='application/atom+xml' href='http://markgamache.blogspot.com/feeds/2916609761133859419/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/5043195767541326568/2916609761133859419' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2916609761133859419'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5043195767541326568/posts/default/2916609761133859419'/><link rel='alternate' type='text/html' href='http://markgamache.blogspot.com/2012/03/proper-pki-configuration-for-ssltls.html' title='Proper PKI Configuration for SSL/TLS Servers'/><author><name>Mark Gamache</name><uri>http://www.blogger.com/profile/12517057928398775070</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJFA3YyxOcU6EIkPYf6sfWje1mwYnlLp6_ZAnDY0rjCTGGay4cTpQG_uCj3cpsXAnfj_ZFaQH1mQMNN06mqtKfTtk4oKDwzHVnqkYuc7rUaI_XMlp84IFzpY8QY5ijH3g/s113/20130528_104723.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjReRrTzqmwVJFFWLSb1SYAzSp8mKzlUd1q9k603ttHSvi0YNb3hBvgiGy7zTqPoJ9WCgxKgEfPO6fEmVISLxw44-iyPsIEKSdIWua8qWTxG9S9VtW9lPdp6ROfmY2Q2Pl8lo0BUMhCpGg/s72-c/1.gif" height="72" width="72"/><thr:total>5</thr:total></entry></feed>