<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Info on Cliff Hults</title><link>https://www.haguest.com/categories/info/</link><description>Recent content in Info on Cliff Hults</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026</copyright><lastBuildDate>Thu, 16 Dec 2021 14:59:43 -0500</lastBuildDate><atom:link href="https://www.haguest.com/categories/info/index.xml" rel="self" type="application/rss+xml"/><item><title>Log4j Scanning and Detection</title><link>https://www.haguest.com/posts/2021-12-16-log4j/</link><pubDate>Thu, 16 Dec 2021 14:59:43 -0500</pubDate><guid>https://www.haguest.com/posts/2021-12-16-log4j/</guid><description>&lt;p>Lately, everyone has been talking about Log4Shell (CVE-2021-44228) and likely, if you&amp;rsquo;re reading this,
you&amp;rsquo;re looking for info for what to do. Most people attempted to utilize Huntress&amp;rsquo;s Log4Shell tool
(&lt;a href="https://log4shell.huntress.com/" target="_blank" rel="noreferrer">https://log4shell.huntress.com/&lt;/a>) to show connections to a LDAP server they were hosting. Some people
had issues with this as it was overburdened with requests (rightfully so) or didn&amp;rsquo;t want to, or
aren&amp;rsquo;t allowed to send outbound traffic to a server they didn&amp;rsquo;t own. At our organziation, we were part
of the latter group. In order to comply with our rules, we needed to find a reliable way to scan our
devices for the vulnerability and look for requests to a domain that we owned.&lt;/p></description></item><item><title>ADFS &amp; CVE-2020-17049</title><link>https://www.haguest.com/posts/2020-11-20-adfs-cve-2020-17049/</link><pubDate>Fri, 20 Nov 2020 18:10:12 -0500</pubDate><guid>https://www.haguest.com/posts/2020-11-20-adfs-cve-2020-17049/</guid><description>&lt;p>Microsoft recently performed a patch for Kerberos and the KDC service on domain controllers. This would patch a heavy vulnerability in the Kerberos signing
structure. However, this presented a problem with our domain joined Qumulo storage
appliance, and disallowed any users from authenticating to SMB shares. In order
to alleviate ourselves of the issue, we followed the instructions to disable
the following registry key within &lt;code>HKLM\SYSTEM\CurrentControlSet\Services\Kdc\&lt;/code>
by adding &lt;code>PerformTicketSignature&lt;/code> set to &lt;code>DWORD 0&lt;/code>.&lt;/p></description></item><item><title>Initial Commit!</title><link>https://www.haguest.com/posts/2019-09-07-initial-commit/</link><pubDate>Sat, 07 Sep 2019 04:00:00 +0000</pubDate><guid>https://www.haguest.com/posts/2019-09-07-initial-commit/</guid><description>&lt;p>Finally getting to use this site! Been looking forward to creating some posts here to document travels of random sets of information. Hopefully to provide some steering for those who during their travels ended up in the same situation and went looking for info.&lt;/p></description></item></channel></rss>