Chapter 1. Windows Operating System – Password Attacks
How Windows Password Attacks Work
Dangers with Windows Password Attacks
Scenario 1: Obtaining Password Hashes
Future of Windows Password Attacks
Defenses Against Windows Password Attacks
Microsoft and Third-Party Software Patching
Implementing Password and Lockout Policies
Chapter 2. Active Directory – Escalation of Privilege
Escalation of Privileges Attack Anatomy
Dangers with Privilege Escalation Attacks
Scenario 1: Escalation through Batch Scripts
Future of Privilege Escalation Attacks
Defenses Against Escalation of Privilege Attacks
First Defensive Layer: Stop the Enemy at the Gate
Second Defensive Layer: Privileges Must Be Earned
Third Defensive Layer: Set the Rules for the Playground
Fourth Defensive Layer: You'll Need That Secret Decoder Ring
Chapter 3. SQL Server – Stored Procedure Attacks
How Stored Procedure Attacks Work
Dangers Associated with a Stored Procedure Attack
Understanding Stored Procedure Vulnerabilities
Scenario 1: Adding a Local Administrator
The Future of Stored Procedure Attacks
Defenses Against Stored Procedure Attacks
First Defensive Layer: Eliminating First-Layer Attacks
Second Defensive Layer: Reduce the First-Layer Attack Surface
Third Defensive Layer: Reducing Second-Layer Attacks
Fourth Defensive Layer: Logging, Monitoring, and Alerting
Chapter 4. Exchange Server – Mail Service Attacks
Dangers Associated with Mail Service Attacks
The Future of Mail Service Attacks
Defenses Against Mail Service Attacks
Defense in the Perimeter Network
Chapter 5. Office – Macros and ActiveX
Macro and Client-Side Attack Anatomy
Dangers Associated with Macros and ActiveX
Future of Macro and ActiveX Attacks
Deploy Network Edge Strategies
Using Antivirus and Antimalware
Chapter 6. Internet Information Services – Web Service Attacks
Scenario 1: Dangerous HTTP Methods
Chapter 7. SharePoint – Multi-tier Attacks
Dangers with Multi-tier Attacks
How Multi-tier Attacks Will Be Used in the Future
Defenses Against Multi-tier Attacks
First Defensive Layer: Failure to Plan = Plan to Fail