{"id":27,"title":"LAN Manager Authentication (Misconfiguration)","content":"<p>&nbsp;<\/p>\n<h1>Kimlik Do\u011frulama Protokol&uuml; G&uuml;venli\u011fi<\/h1>\n<h2>LAN Manager Authentication Level G&uuml;venlik A&ccedil;\u0131\u011f\u0131<\/h2>\n<p>Windows a\u011f ortamlar\u0131nda <strong>kimlik do\u011frulama g&uuml;venli\u011fi<\/strong>, sistem b&uuml;t&uuml;nl&uuml;\u011f&uuml;n&uuml;n en kritik unsurlar\u0131ndan biridir. <strong>LAN Manager Authentication Level<\/strong> ayar\u0131n\u0131n g&uuml;venli seviyeye ayarlanmamas\u0131, sald\u0131rganlar\u0131n <strong>eski ve zay\u0131f kimlik do\u011frulama protokollerini<\/strong> kullanarak sisteme s\u0131zmas\u0131na olanak tan\u0131r.<\/p>\n<p>Bu yaz\u0131da, bu <strong>kritik g&uuml;venlik a&ccedil;\u0131\u011f\u0131n\u0131<\/strong> ve <strong>etkili &ccedil;&ouml;z&uuml;m y&ouml;ntemlerini<\/strong> detayl\u0131 olarak inceleyece\u011fiz.<\/p>\n<hr>\n<h2>LAN Manager Authentication Level Nedir?<\/h2>\n<p><strong>LAN Manager Authentication Level<\/strong>, Windows sistemlerinin <strong>hangi kimlik do\u011frulama protokollerini kabul edece\u011fini<\/strong> belirleyen kritik bir g&uuml;venlik ayar\u0131d\u0131r. Bu ayar, a\u011f kaynaklar\u0131na eri\u015fim s\u0131ras\u0131nda kullan\u0131lacak <strong>kimlik do\u011frulama y&ouml;ntemini<\/strong> kontrol eder.<\/p>\n<hr>\n<h2>Kimlik Do\u011frulama Protokolleri<\/h2>\n<p>Windows ortamlar\u0131nda <strong>&uuml;&ccedil; temel kimlik do\u011frulama protokol&uuml;<\/strong> bulunur:<\/p>\n<hr>\n<h3>1. LM (LAN Manager) &ndash; En Zay\u0131f<\/h3>\n<ul>\n<li>\n<p><strong>Geli\u015ftirme Tarihi:<\/strong> 1980&rsquo;ler<\/p>\n<\/li>\n<li>\n<p><strong>\u015eifre Uzunlu\u011fu:<\/strong> Maksimum 14 karakter<\/p>\n<\/li>\n<li>\n<p><strong>\u015eifreleme:<\/strong> DES tabanl\u0131, &ccedil;ok zay\u0131f<\/p>\n<\/li>\n<li>\n<p><strong>G&uuml;venlik Riski:<\/strong> \u274c &Ccedil;ok y&uuml;ksek<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h3>2. NTLM (NT LAN Manager) &ndash; Orta Seviye<\/h3>\n<ul>\n<li>\n<p><strong>Geli\u015ftirme Tarihi:<\/strong> 1990&rsquo;lar<\/p>\n<\/li>\n<li>\n<p><strong>\u015eifre Uzunlu\u011fu:<\/strong> S\u0131n\u0131rs\u0131z<\/p>\n<\/li>\n<li>\n<p><strong>\u015eifreleme:<\/strong> MD4 tabanl\u0131<\/p>\n<\/li>\n<li>\n<p><strong>G&uuml;venlik Riski:<\/strong> \u26a0\ufe0f Orta&ndash;Y&uuml;ksek<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h3>3. NTLMv2 (NT LAN Manager v2) &ndash; En G&uuml;venli<\/h3>\n<ul>\n<li>\n<p><strong>Geli\u015ftirme Tarihi:<\/strong> 1998<\/p>\n<\/li>\n<li>\n<p><strong>\u015eifre Uzunlu\u011fu:<\/strong> S\u0131n\u0131rs\u0131z<\/p>\n<\/li>\n<li>\n<p><strong>\u015eifreleme:<\/strong> HMAC-MD5 tabanl\u0131<\/p>\n<\/li>\n<li>\n<p><strong>G&uuml;venlik Riski:<\/strong> \u2705 D&uuml;\u015f&uuml;k (mevcut protokoller aras\u0131nda)<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h2>G&uuml;venlik Riskleri ve Sald\u0131r\u0131 Y&ouml;ntemleri<\/h2>\n<h3>1. LM Protokol&uuml; Zafiyetleri<\/h3>\n<h4>Pass-the-Hash Sald\u0131r\u0131lar\u0131<\/h4>\n<ul>\n<li>\n<p>LM hash de\u011ferleri kolayca ele ge&ccedil;irilebilir<\/p>\n<\/li>\n<li>\n<p>Ger&ccedil;ek parolaya ihtiya&ccedil; duyulmaz<\/p>\n<\/li>\n<li>\n<p>Lateral movement i&ccedil;in kullan\u0131labilir<\/p>\n<\/li>\n<\/ul>\n<h4>Brute Force Sald\u0131r\u0131lar\u0131<\/h4>\n<ul>\n<li>\n<p>14 karakter s\u0131n\u0131r\u0131 nedeniyle d&uuml;\u015f&uuml;k karma\u015f\u0131kl\u0131k<\/p>\n<\/li>\n<li>\n<p>DES \u015fifreleme modern sistemlerde h\u0131zl\u0131 k\u0131r\u0131l\u0131r<\/p>\n<\/li>\n<li>\n<p>Rainbow table sald\u0131r\u0131lar\u0131 olduk&ccedil;a etkilidir<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h3>2. NTLM Protokol&uuml; Zafiyetleri<\/h3>\n<h4>Replay Sald\u0131r\u0131lar\u0131<\/h4>\n<ul>\n<li>\n<p>Kimlik do\u011frulama paketleri yakalan\u0131p tekrar kullan\u0131labilir<\/p>\n<\/li>\n<li>\n<p>Zaman damgas\u0131 korumas\u0131 zay\u0131ft\u0131r<\/p>\n<\/li>\n<li>\n<p>Challenge-response mekanizmas\u0131 bypass edilebilir<\/p>\n<\/li>\n<\/ul>\n<h4>Relay Sald\u0131r\u0131lar\u0131<\/h4>\n<ul>\n<li>\n<p>NTLM trafi\u011fi ba\u015fka sistemlere y&ouml;nlendirilebilir<\/p>\n<\/li>\n<li>\n<p>SMB relay sald\u0131r\u0131lar\u0131 ger&ccedil;ekle\u015ftirilebilir<\/p>\n<\/li>\n<li>\n<p>Sald\u0131rgan kendisini hedef sistem gibi g&ouml;sterebilir<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h3>3. NTLMv2 Avantajlar\u0131<\/h3>\n<h4>G&uuml;&ccedil;l&uuml; \u015eifreleme<\/h4>\n<ul>\n<li>\n<p>HMAC-MD5 tabanl\u0131 geli\u015fmi\u015f \u015fifreleme<\/p>\n<\/li>\n<li>\n<p>Mutual authentication deste\u011fi<\/p>\n<\/li>\n<li>\n<p>Replay sald\u0131r\u0131lar\u0131na kar\u015f\u0131 koruma<\/p>\n<\/li>\n<\/ul>\n<h4>Geli\u015fmi\u015f Challenge-Response<\/h4>\n<ul>\n<li>\n<p>G&uuml;&ccedil;l&uuml; nonce de\u011ferleri<\/p>\n<\/li>\n<li>\n<p>Zaman damgas\u0131 do\u011frulamas\u0131<\/p>\n<\/li>\n<li>\n<p>Replay ve relay sald\u0131r\u0131lar\u0131na kar\u015f\u0131 diren&ccedil;<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h2>&Ccedil;&ouml;z&uuml;m Y&ouml;ntemleri<\/h2>\n<h3>1. Group Policy (GPO) ile Yap\u0131land\u0131rma<\/h3>\n<p><strong>Ad\u0131m 1:<\/strong> Group Policy Management Console<\/p>\n<pre><code>gpmc.msc\n<\/code><\/pre>\n<p><strong>Ad\u0131m 2:<\/strong> Politika D&uuml;zenleme<\/p>\n<pre><code>Computer Configuration\n&rarr; Windows Settings\n&rarr; Security Settings\n&rarr; Local Policies\n&rarr; Security Options\n<\/code><\/pre>\n<p><strong>Ad\u0131m 3:<\/strong><br><strong>&ldquo;Network security: LAN Manager authentication level&rdquo;<\/strong> politikas\u0131n\u0131 bulun.<\/p>\n<p><strong>G&uuml;venli Ayar:<\/strong><\/p>\n<pre><code>Send NTLMv2 response only. Refuse LM &amp; NTLM\n<\/code><\/pre>\n<hr>\n<h3>2. Registry &Uuml;zerinden Yap\u0131land\u0131rma<\/h3>\n<p><strong>Registry Anahtar\u0131:<\/strong><\/p>\n<pre><code>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\n<\/code><\/pre>\n<p><strong>De\u011ferler:<\/strong><\/p>\n<ul>\n<li>\n<p><strong>De\u011fer Ad\u0131:<\/strong> LmCompatibilityLevel<\/p>\n<\/li>\n<li>\n<p><strong>T&uuml;r:<\/strong> REG_DWORD<\/p>\n<\/li>\n<li>\n<p><strong>&Ouml;nerilen De\u011fer:<\/strong> 5<\/p>\n<\/li>\n<\/ul>\n<p><strong>PowerShell ile Uygulama:<\/strong><\/p>\n<pre><code>Set-ItemProperty -Path \"HKLM:\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" `\n -Name \"LmCompatibilityLevel\" -Value 5\n<\/code><\/pre>\n<hr>\n<h3>3. G&uuml;venlik Seviyeleri Tablosu<\/h3>\n<table>\n<thead>\n<tr>\n<th>Seviye<\/th>\n<th>A&ccedil;\u0131klama<\/th>\n<th>G&uuml;venlik<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>0<\/td>\n<td>LM ve NTLM g&ouml;nder<\/td>\n<td>\u274c &Ccedil;ok g&uuml;vensiz<\/td>\n<\/tr>\n<tr>\n<td>1<\/td>\n<td>LM &amp; NTLM g&ouml;nder, NTLMv2 kullan<\/td>\n<td>\u274c G&uuml;vensiz<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td>Sadece NTLM g&ouml;nder<\/td>\n<td>\u26a0\ufe0f Orta risk<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>Sadece NTLMv2 g&ouml;nder<\/td>\n<td>\u26a0\ufe0f Orta risk<\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td>NTLMv2 g&ouml;nder, LM reddet<\/td>\n<td>\u2705 G&uuml;venli<\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>NTLMv2 g&ouml;nder, LM &amp; NTLM reddet<\/td>\n<td>\u2705 <strong>En g&uuml;venli<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<h2>Domain Controller Ayarlar\u0131<\/h2>\n<h3>DC i&ccedil;in Minimum G&uuml;venli Seviye<\/h3>\n<pre><code>Network security: LAN Manager authentication level = 4\n<\/code><\/pre>\n<h3>Ek G&uuml;venlik Ayarlar\u0131<\/h3>\n<ul>\n<li>\n<p><strong>Do not store LAN Manager hash value on next password change<\/strong> &rarr; Enabled<\/p>\n<\/li>\n<li>\n<p><strong>Network security: Do not store LAN Manager hash value on next password change<\/strong> &rarr; Enabled<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h2>Active Directory Functional Level<\/h2>\n<p>NTLMv2 zorunlulu\u011fu i&ccedil;in:<\/p>\n<ul>\n<li>\n<p><strong>Domain Functional Level:<\/strong> En az Windows 2000 Native<\/p>\n<\/li>\n<li>\n<p><strong>Forest Functional Level:<\/strong> En az Windows 2000<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h2>Deployment Sonras\u0131 Dikkat Edilmesi Gerekenler<\/h2>\n<h3>1. Legacy Sistem Uyumlulu\u011fu<\/h3>\n<p><strong>Etkilenebilecek Sistemler:<\/strong><\/p>\n<ul>\n<li>\n<p>Windows 95 \/ 98 \/ ME<\/p>\n<\/li>\n<li>\n<p>Windows NT 4.0 (SP4 &ouml;ncesi)<\/p>\n<\/li>\n<li>\n<p>Samba 3.0 &ouml;ncesi Linux sistemler<\/p>\n<\/li>\n<li>\n<p>Yaz\u0131c\u0131lar, NAS cihazlar\u0131, g&ouml;m&uuml;l&uuml; sistemler<\/p>\n<\/li>\n<\/ul>\n<p><strong>&Ccedil;&ouml;z&uuml;m Stratejileri:<\/strong><\/p>\n<ul>\n<li>\n<p>Sistem envanteri &ccedil;\u0131kar\u0131n<\/p>\n<\/li>\n<li>\n<p>Test ortam\u0131nda uygulay\u0131n<\/p>\n<\/li>\n<li>\n<p>Kimlik do\u011frulama hatalar\u0131n\u0131 izleyin<\/p>\n<\/li>\n<li>\n<p>Legacy sistemler i&ccedil;in upgrade plan\u0131 yap\u0131n<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h3>2. Uygulama Uyumlulu\u011fu<\/h3>\n<p>Kontrol edilmesi gerekenler:<\/p>\n<ul>\n<li>\n<p>Third-party uygulamalar<\/p>\n<\/li>\n<li>\n<p>Veritaban\u0131 ba\u011flant\u0131lar\u0131<\/p>\n<\/li>\n<li>\n<p>Web uygulamalar\u0131<\/p>\n<\/li>\n<li>\n<p>Yedekleme yaz\u0131l\u0131mlar\u0131<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h3>3. Monitoring ve Logging<\/h3>\n<p><strong>\u0130lgili Event ID&rsquo;ler:<\/strong><\/p>\n<ul>\n<li>\n<p><strong>4776:<\/strong> Credential validation attempted<\/p>\n<\/li>\n<li>\n<p><strong>4625:<\/strong> Failed logon attempt<\/p>\n<\/li>\n<li>\n<p><strong>4648:<\/strong> Explicit credentials<\/p>\n<\/li>\n<\/ul>\n<p><strong>PowerShell Monitoring:<\/strong><\/p>\n<pre><code>Get-WinEvent -FilterHashtable @{LogName='Security'; ID=4776} |\n Where-Object {$_.Message -like \"*LM*\" -or $_.Message -like \"*NTLM*\"}\n<\/code><\/pre>\n<hr>\n<h2>G&uuml;venlik Do\u011frulama<\/h2>\n<h3>1. Mevcut Ayarlar\u0131n Kontrol&uuml;<\/h3>\n<p><strong>GPO ile:<\/strong><\/p>\n<pre><code>gpresult \/h gpreport.html\n<\/code><\/pre>\n<p><strong>Registry ile:<\/strong><\/p>\n<pre><code>Get-ItemProperty -Path \"HKLM:\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" `\n -Name \"LmCompatibilityLevel\"\n<\/code><\/pre>\n<hr>\n<h3>2. A\u011f Trafi\u011fi Analizi<\/h3>\n<ul>\n<li>\n<p>Wireshark ile NTLM paketlerini yakalay\u0131n<\/p>\n<\/li>\n<li>\n<p>Protokol s&uuml;r&uuml;m&uuml;n&uuml; do\u011frulay\u0131n<\/p>\n<\/li>\n<li>\n<p>Challenge-response mekanizmas\u0131n\u0131 inceleyin<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h3>3. G&uuml;venlik Tarama<\/h3>\n<p><strong>Nmap ile:<\/strong><\/p>\n<pre><code>nmap --script smb-security-mode\n<\/code><\/pre>\n<p><strong>PowerShell Bulk Kontrol:<\/strong><\/p>\n<pre><code>$computers = Get-ADComputer -Filter * | Select-Object -ExpandProperty Name\nforeach ($computer in $computers) {\n  try {\n    $lmLevel = Invoke-Command -ComputerName $computer -ScriptBlock {\n      Get-ItemProperty -Path \"HKLM:\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" `\n       -Name \"LmCompatibilityLevel\"\n    }\n    Write-Output \"$computer : $($lmLevel.LmCompatibilityLevel)\"\n  } catch {\n    Write-Output \"$computer : Connection failed\"\n  }\n}\n<\/code><\/pre>\n<hr>\n<h2>Sonu&ccedil; ve &Ouml;neriler<\/h2>\n<p><strong>LAN Manager Authentication Level<\/strong> ayar\u0131n\u0131n <strong>Seviye 5<\/strong> olarak yap\u0131land\u0131r\u0131lmas\u0131, Windows a\u011f g&uuml;venli\u011finin <strong>temel gereksinimlerinden biridir<\/strong>.<\/p>\n<p><strong>&ldquo;Send NTLMv2 response only. Refuse LM &amp; NTLM&rdquo;<\/strong> yap\u0131land\u0131rmas\u0131, modern g&uuml;venlik standartlar\u0131na uygun <strong>minimum g&uuml;venli seviye<\/strong> olarak kabul edilir.<\/p>\n<hr>\n<h3>H\u0131zl\u0131 Uygulama Ad\u0131mlar\u0131<\/h3>\n<p>\u2705 Mevcut durumu analiz edin<br>\u2705 Test ortam\u0131nda uygulay\u0131n<br>\u2705 Legacy sistemleri tespit edin<br>\u2705 GPO ile seviye 5&rsquo;e ayarlay\u0131n<br>\u2705 Monitoring sistemini kurun<br>\u2705 A\u015famal\u0131 deployment ger&ccedil;ekle\u015ftirin<\/p>\n<hr>\n<h3>Kritik Kontrol Listesi<\/h3>\n<p>\u2705 <code>LmCompatibilityLevel = 5<\/code> mi?<br>\u2705 Domain GPO&rsquo;da politika aktif mi?<br>\u2705 Legacy sistemler g&uuml;ncellendi mi?<br>\u2705 Monitoring aktif mi?<br>\u2705 Incident response plan\u0131 haz\u0131r m\u0131?<\/p>\n<hr>\n<p>Bu yap\u0131land\u0131rmay\u0131 uygulayarak <strong>pass-the-hash<\/strong>, <strong>replay<\/strong> ve <strong>relay<\/strong> sald\u0131r\u0131lar\u0131na kar\u015f\u0131 sisteminizi &ouml;nemli &ouml;l&ccedil;&uuml;de koruyabilir ve <strong>modern kimlik do\u011frulama standartlar\u0131na uygun<\/strong> bir g&uuml;venlik seviyesi sa\u011flayabilirsiniz.<\/p>","excerpt":"Windows a\u011f ortamlar\u0131nda kimlik do\u011frulama g\u00fcvenli\u011fi, sistem b\u00fct\u00fcnl\u00fc\u011f\u00fcn\u00fcn en kritik unsurlar\u0131ndan biridir. LAN Manager Authentication Level ayar\u0131n\u0131n g\u00fcvenli seviyeye ayarlanmamas\u0131, sald\u0131rganlar\u0131n eski ve zay\u0131f kimlik do\u011frulama protokollerini kullanarak sisteme s\u0131zmas\u0131na olanak tan\u0131r.","created_at":"2025-07-16 23:49:29","updated_at":"2026-09-23 15:28:56","category_id":12,"view_count":643,"reading_time":6,"status":"published","editor_choice":0,"is_editor_choice":0,"published_at":"2025-07-16 23:49:29","featured_image":"\/uploads\/images\/2025\/12\/6947c5a1a2465_1766311329.png","slug":"lan-manager-authentication-misconfiguration","category_name":"Misconfiguration","category_slug":"misconfiguration","category_color":"#84cc16"}