<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Credential Theft on Locodigital</title><link>https://locodigital.com.br/en/tags/credential-theft/</link><description>Recent content in Credential Theft on Locodigital</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Thu, 17 Sep 2026 10:00:00 -0300</lastBuildDate><atom:link href="https://locodigital.com.br/en/tags/credential-theft/index.xml" rel="self" type="application/rss+xml"/><item><title>Pass-the-Hash: how the NTLM attack works without the password</title><link>https://locodigital.com.br/en/technology/pass-the-hash-how-the-ntlm-attack-works/</link><pubDate>Thu, 17 Sep 2026 10:00:00 -0300</pubDate><guid>https://locodigital.com.br/en/technology/pass-the-hash-how-the-ntlm-attack-works/</guid><description>&lt;p&gt;An attacker compromises a workstation on the corporate network. They don't have the domain administrator's password — but that doesn't matter. With the NTLM hash extracted from memory, they authenticate to dozens of servers as if they were the administrator themselves. This is Pass-the-Hash: an attack that has existed since 1997, documented by researcher Paul Ashton, and that still fuels the early stages of ransomware attacks and APT campaigns today.&lt;/p&gt;</description></item></channel></rss>