[{"id":407,"title":"Windows Server 24H2 G\u00fcvenlik Alarm\u0131 ? KB5066835 Yamas\u0131","content":"<div id=\"model-response-message-contentr_23aa18ca0c31b55d\" class=\"markdown markdown-main-panel enable-luminous-fast-follows enable-updated-hr-color stronger\" dir=\"ltr\" aria-busy=\"false\" aria-live=\"polite\">\n<p data-path-to-node=\"3\">Siber g&uuml;venlik d&uuml;nyas\u0131nda zafiyetlerin \"ya\u015f\u0131\" her zaman riskin bitti\u011fi anlam\u0131na gelmez. Bunun en g&uuml;ncel &ouml;rne\u011fini, Microsoft&rsquo;un modern i\u015fletim sistemleri i&ccedil;in yay\u0131nlad\u0131\u011f\u0131 son toplu g&uuml;ncelle\u015ftirmelerde a&ccedil;\u0131k&ccedil;a g&ouml;r&uuml;yoruz. K&ouml;keni 2016 y\u0131l\u0131na dayanan bir a&ccedil;\u0131k kaynak k&uuml;t&uuml;phanesi zafiyeti, bug&uuml;n en g&uuml;ncel&nbsp;<strong data-path-to-node=\"3\" data-index-in-node=\"299\">Windows Server 24H2<\/strong> sistemlerimizi do\u011frudan etkileyebiliyor.<\/p>\n<p data-path-to-node=\"4\">Bu yaz\u0131m\u0131zda, sistem y&ouml;neticilerinin radar\u0131nda olmas\u0131 gereken <strong data-path-to-node=\"4\" data-index-in-node=\"62\">CVE-2016-9535<\/strong> zafiyetini ve &ccedil;&ouml;z&uuml;m ad\u0131mlar\u0131n\u0131 ele al\u0131yoruz.<\/p>\n<h3 data-path-to-node=\"6\">Tehlike Nedir? (CVE-2016-9535 ve LibTIFF)<\/h3>\n<p data-path-to-node=\"7\">Zafiyetin merkezinde, g&ouml;rsel i\u015fleme s&uuml;re&ccedil;lerinde yayg\u0131n olarak kullan\u0131lan a&ccedil;\u0131k kaynakl\u0131 bir k&uuml;t&uuml;phane olan <strong data-path-to-node=\"7\" data-index-in-node=\"107\">LibTIFF<\/strong> yer al\u0131yor. Bu k&uuml;t&uuml;phanenin eski s&uuml;r&uuml;mlerinde (<code data-path-to-node=\"7\" data-index-in-node=\"162\">tif_predict.c<\/code> kaynakl\u0131), k&ouml;t&uuml; ama&ccedil;l\u0131 yap\u0131land\u0131r\u0131lm\u0131\u015f bir TIFF g&ouml;rseli i\u015flenirken bellek boyutu yanl\u0131\u015f hesaplan\u0131yor.<\/p>\n<p data-path-to-node=\"8\">Sonu&ccedil;? <strong data-path-to-node=\"8\" data-index-in-node=\"7\">Kritik (CVSS: 9.8) seviyede bir Y\u0131\u011f\u0131n Tabanl\u0131 Arabellek Ta\u015fmas\u0131 (Heap-based Buffer Overflow).<\/strong><\/p>\n<p data-path-to-node=\"9\">Sald\u0131rganlar, bu a&ccedil;\u0131\u011f\u0131 manip&uuml;le ederek sistem &uuml;zerinde <strong data-path-to-node=\"9\" data-index-in-node=\"55\">Uzaktan Kod &Ccedil;al\u0131\u015ft\u0131rma (RCE)<\/strong> ger&ccedil;ekle\u015ftirebilir veya sistem servislerini tamamen &ccedil;&ouml;kerterek hizmet d\u0131\u015f\u0131 (DoS) b\u0131rakabilir.<\/p>\n<h3 data-path-to-node=\"10\">En G&uuml;ncel Sistemler Neden Etkileniyor?<\/h3>\n<p data-path-to-node=\"11\">Peki, 2016'n\u0131n a&ccedil;\u0131\u011f\u0131 neden 24H2 mimarisinde kar\u015f\u0131m\u0131za &ccedil;\u0131k\u0131yor?<\/p>\n<p data-path-to-node=\"12\">Bunun nedeni <strong data-path-to-node=\"12\" data-index-in-node=\"13\">yaz\u0131l\u0131m tedarik zinciri (Supply Chain)<\/strong> ba\u011f\u0131ml\u0131l\u0131klar\u0131d\u0131r. \u0130\u015fletim sistemlerinin alt katmanlar\u0131nda yer alan faks, yazd\u0131rma alt yap\u0131lar\u0131 veya dahili imaj g&ouml;r&uuml;nt&uuml;leme bile\u015fenleri, arka planda h&acirc;l&acirc; bu k&ouml;kl&uuml; k&uuml;t&uuml;phanelerin kod par&ccedil;ac\u0131klar\u0131n\u0131 bar\u0131nd\u0131rabiliyor. Microsoft, modern i\u015fletim sistemlerini tamamen g&uuml;venli hale getirmek ad\u0131na bu eski kal\u0131nt\u0131lar\u0131 da geriye d&ouml;n&uuml;k olarak temizlemektedir.<\/p>\n<h3 data-path-to-node=\"14\">&Ccedil;&ouml;z&uuml;m: KB5066835 G&uuml;ncelle\u015ftirmesi<\/h3>\n<p data-path-to-node=\"15\">Microsoft, x64 tabanl\u0131 Windows Server 24H2 ve Windows 11 sistemler i&ccedil;in bu a&ccedil;\u0131\u011f\u0131 kapatan <strong data-path-to-node=\"15\" data-index-in-node=\"89\">KB5066835<\/strong> toplu g&uuml;ncelle\u015ftirme paketini devreye ald\u0131.<\/p>\n<p data-path-to-node=\"16\">Bu yama, alt bile\u015fenlerdeki bellek tahsis aritmeti\u011fini ve s\u0131n\u0131r kontrollerini d&uuml;zelterek g&uuml;venlik a&ccedil;\u0131\u011f\u0131n\u0131 tamamen ortadan kald\u0131r\u0131yor. G&uuml;ncelleme ba\u015far\u0131yla uyguland\u0131\u011f\u0131nda, i\u015fletim sistemi derleme numaran\u0131z <strong data-path-to-node=\"16\" data-index-in-node=\"205\">26100.6899<\/strong> (veya &uuml;zeri) seviyesine y&uuml;kselmektedir.<\/p>\n<h3 data-path-to-node=\"18\">Sistem Y&ouml;neticileri \u0130&ccedil;in 3 Ad\u0131ml\u0131 Aksiyon Plan\u0131<\/h3>\n<p data-path-to-node=\"19\">E\u011fer altyap\u0131n\u0131zda Windows Server 24H2 veya Windows 11 24H2 &ccedil;al\u0131\u015ft\u0131ran sunucu ve istemciler varsa, a\u015fa\u011f\u0131daki ad\u0131mlar\u0131 h\u0131zla uygulaman\u0131z\u0131 &ouml;neririz:<\/p>\n<ol start=\"1\" data-path-to-node=\"20\">\n<li>\n<p data-path-to-node=\"20,0,0\"><strong data-path-to-node=\"20,0,0\" data-index-in-node=\"0\">Envanter Kontrol&uuml;:<\/strong> WSUS, SCCM veya Microsoft Defender for Endpoint &uuml;zerinden sistemlerinizin derleme (build) numaralar\u0131n\u0131 filtreleyin.<\/p>\n<\/li>\n<li>\n<p data-path-to-node=\"20,1,0\"><strong data-path-to-node=\"20,1,0\" data-index-in-node=\"0\">Yama Da\u011f\u0131t\u0131m\u0131:<\/strong> Test ortamlar\u0131nda do\u011frulamas\u0131 yap\u0131lan <strong data-path-to-node=\"20,1,0\" data-index-in-node=\"53\">KB5066835<\/strong> g&uuml;ncellemesini &uuml;retim (production) ortam\u0131ndaki sunucular\u0131n\u0131za planl\u0131 bir kesinti pencerelerinde da\u011f\u0131t\u0131n.<\/p>\n<\/li>\n<li>\n<p data-path-to-node=\"20,2,0\"><strong data-path-to-node=\"20,2,0\" data-index-in-node=\"0\">Do\u011frulama:<\/strong> G&uuml;ncelleme sonras\u0131nda sunucularda PowerShell &uuml;zerinden a\u015fa\u011f\u0131daki komutu &ccedil;al\u0131\u015ft\u0131rarak g&uuml;venli derleme s&uuml;r&uuml;m&uuml;ne ula\u015ft\u0131\u011f\u0131n\u0131z\u0131 teyit edin:<\/p>\n<!----><!----><!----><!----><!----><!----><!----><!---->\n<div class=\"code-block ng-tns-c2643669177-22 ng-animate-disabled ng-trigger ng-trigger-codeBlockRevealAnimation\" data-hveid=\"0\" data-ved=\"0CAAQhtANahgKEwj1lp7dwMKVAxUAAAAAHQAAAAAQrwE\"><!---->\n<div class=\"formatted-code-block-internal-container ng-tns-c2643669177-22\">\n<div class=\"animated-opacity ng-tns-c2643669177-22\">\n<div class=\"code-block-decoration header-formatted gds-emphasized-body-m ng-tns-c2643669177-22 ng-star-inserted\"><span class=\"ng-tns-c2643669177-22\">PowerShell<\/span><!----><!----><button class=\"mdc-icon-button mat-mdc-icon-button mat-mdc-button-base mat-badge mat-unthemed _mat-animation-noopable mat-badge-overlap mat-badge-above mat-badge-after mat-badge-small mat-badge-hidden ng-star-inserted\" aria-label=\"Kodu indir\"><!----><!----><!----><!----><\/button><!----><!----><!----><!----><!----><!----><!----><!----><!----><button class=\"mdc-icon-button mat-mdc-icon-button mat-mdc-button-base mat-badge mat-unthemed _mat-animation-noopable mat-badge-overlap mat-badge-above mat-badge-after mat-badge-small mat-badge-hidden ng-star-inserted\" aria-label=\"Kodu kopyala\"><!----><!----><!----><!----><\/button><!----><!----><!----><!----><!----><!----><!----><!----><\/div>\n<div class=\"code-block-decoration header-formatted gds-emphasized-body-m ng-tns-c2643669177-22 ng-star-inserted\"><code class=\"code-container formatted ng-tns-c2643669177-22\" role=\"text\" data-test-id=\"code-content\">(<span class=\"hljs-built_in\">Get-ItemProperty<\/span> <span class=\"hljs-string\">\"HKLM:\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\"<\/span>).UBR\n<\/code><\/div>\n<!----><!----><\/div>\n<\/div>\n<\/div>\n<!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><!----><\/li>\n<\/ol>\n<p data-path-to-node=\"21\">Unutmay\u0131n; siber sald\u0131rganlar sistem s\u0131zmalar\u0131 i&ccedil;in her zaman en karma\u015f\u0131k s\u0131f\u0131r\u0131nc\u0131 g&uuml;n (Zero-Day) a&ccedil;\u0131klar\u0131n\u0131 aramazlar, &ccedil;o\u011fu zaman g&ouml;zden ka&ccedil;an eski ve yamalanmam\u0131\u015f k&uuml;t&uuml;phaneleri kullan\u0131rlar. Sistemlerinizi g&uuml;ncel tutun, altyap\u0131n\u0131z\u0131 g&uuml;vende b\u0131rak\u0131n!!!<\/p>\n<\/div>","excerpt":"Siber g\u00fcvenlik d\u00fcnyas\u0131nda zafiyetlerin \"ya\u015f\u0131\" her zaman riskin bitti\u011fi anlam\u0131na gelmez. Bunun en g\u00fcncel \u00f6rne\u011fini, Microsoft\u2019un modern i\u015fletim sistemleri i\u00e7in yay\u0131nlad\u0131\u011f\u0131 son toplu g\u00fcncelle\u015ftirmelerde a\u00e7\u0131k\u00e7a g\u00f6r\u00fcyoruz. K\u00f6keni 2016 y\u0131l\u0131na dayanan bir a\u00e7\u0131k kaynak k\u00fct\u00fcphanesi zafiyeti, bug\u00fcn en g\u00fcncel\u00a0Windows Server 24H2 sistemlerimizi do\u011frudan etkileyebiliyor.","created_at":"2026-07-08 10:11:25","updated_at":"2026-09-08 00:36:08","category_id":12,"view_count":252,"reading_time":4,"status":"published","editor_choice":0,"is_editor_choice":0,"published_at":"2026-07-08 07:11:25","featured_image":"\/uploads\/images\/2026\/07\/6a4df819b9d6e_1783494681.jpg","slug":"windows-server-24h2-guvenlik-alarmi-kb5066835-yamasi","category_name":"Misconfiguration","category_slug":"misconfiguration","category_color":"#84cc16"},{"id":20,"title":"User Account Control (UAC) G\u00fcvenlik A\u00e7\u0131\u011f\u0131 (Misconfiguration)","content":"<p>&nbsp;<\/p>\n<h1>User Account Control (UAC) G&uuml;venlik A&ccedil;\u0131\u011f\u0131: Secure Desktop ile Privilege Escalation Korumas\u0131<\/h1>\n<p>User Account Control (UAC), Windows i\u015fletim sistemlerinin en kritik g&uuml;venlik mekanizmalar\u0131ndan biridir. UAC'nin secure desktop &uuml;zerinde y&ouml;netici onay\u0131 isteyecek \u015fekilde yap\u0131land\u0131r\u0131lmamas\u0131, malicious software'in fark edilmeden y&uuml;ksek yetkilerle &ccedil;al\u0131\u015fmas\u0131na olanak tan\u0131r.<\/p>\n<p>Admin Approval Mode ile birlikte do\u011fru yap\u0131land\u0131r\u0131lan UAC, privilege escalation sald\u0131r\u0131lar\u0131na kar\u015f\u0131 g&uuml;&ccedil;l&uuml; bir savunma olu\u015fturur. Bu yaz\u0131da, UAC g&uuml;venlik a&ccedil;\u0131\u011f\u0131n\u0131 ve <strong>&ldquo;Prompt for consent on the secure desktop&rdquo;<\/strong> yap\u0131land\u0131rmas\u0131n\u0131n &ouml;nemini detayl\u0131 olarak inceleyece\u011fiz.<\/p>\n<hr>\n<h2>User Account Control (UAC) Architecture<\/h2>\n<h3>UAC Security Model<\/h3>\n<h4>Core Components<\/h4>\n<pre><code>UAC Security Stack:\n\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n\u2502 Application Request                 \u2502\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 Admin Approval Mode                 \u2502 &larr; Critical Security Layer\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 Secure Desktop                      \u2502 &larr; Isolation Mechanism\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 Elevation Prompt                    \u2502 &larr; User Interaction\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 Privilege Token Management          \u2502 &larr; Permission Granting\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\n<\/code><\/pre>\n<hr>\n<h3>Token Architecture<\/h3>\n<pre><code># UAC token structure\nfunction Analyze-UACTokens {\n\n    $tokenInfo = @{\n        \"Standard_User_Token\" = @{\n            Description = \"Limited privileges for daily operations\"\n            Capabilities = @(\n                \"File access\",\n                \"Registry read\",\n                \"Network access\"\n            )\n            Restrictions = @(\n                \"No system modification\",\n                \"No driver installation\",\n                \"No security policy changes\"\n            )\n        }\n\n        \"Administrator_Token\" = @{\n            Description = \"Full administrative privileges\"\n            Capabilities = @(\n                \"System modification\",\n                \"Driver installation\",\n                \"Security policy changes\",\n                \"Service management\"\n            )\n            Requirements = @(\n                \"UAC elevation\",\n                \"User consent\",\n                \"Secure desktop prompt\"\n            )\n        }\n\n        \"Filtered_Admin_Token\" = @{\n            Description = \"Admin user running with standard privileges\"\n            Elevation_Process = \"UAC prompt &rarr; Secure desktop &rarr; User consent &rarr; Full admin token\"\n        }\n    }\n\n    return $tokenInfo\n}\n<\/code><\/pre>\n<hr>\n<h2>Admin Approval Mode Mechanics<\/h2>\n<h3>Normal vs Admin Approval Mode<\/h3>\n<table>\n<thead>\n<tr>\n<th>Mode<\/th>\n<th>Token Type<\/th>\n<th>Privilege Level<\/th>\n<th>UAC Behavior<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Normal Admin<\/td>\n<td>Full Admin Token<\/td>\n<td>High<\/td>\n<td>\u274c No prompts &ndash; Security risk<\/td>\n<\/tr>\n<tr>\n<td>Admin Approval Mode<\/td>\n<td>Filtered Token &rarr; Full Token<\/td>\n<td>Standard &rarr; High<\/td>\n<td>\u2705 UAC prompts required<\/td>\n<\/tr>\n<tr>\n<td>Standard User<\/td>\n<td>Standard Token<\/td>\n<td>Limited<\/td>\n<td>\u2705 Credential prompt required<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<h2>G&uuml;venlik Riskleri ve Sald\u0131r\u0131 Vekt&ouml;rleri<\/h2>\n<h3>1. Malicious Software Privilege Escalation<\/h3>\n<h4>Silent Elevation Attacks<\/h4>\n<pre><code># UAC bypass simulation scenarios\nfunction Simulate-UACBypassRisks {\n    param($UACLevel)\n\n    $riskScenarios = @{\n        \"Never_Notify\" = @{\n            RiskLevel = \"CRITICAL\"\n            AttackSuccess = \"99%\"\n            Description = \"Malware gains admin privileges silently\"\n            Examples = @(\n                \"Rootkit installation without detection\",\n                \"System file modification\",\n                \"Registry security policy changes\",\n                \"Service hijacking and persistence\"\n            )\n        }\n\n        \"Prompt_Without_Secure_Desktop\" = @{\n            RiskLevel = \"HIGH\"\n            AttackSuccess = \"75%\"\n            Description = \"UI automation attacks can bypass prompts\"\n            Examples = @(\n                \"Automated clicking of UAC dialogs\",\n                \"DLL injection into UAC prompt process\",\n                \"Window message spoofing\",\n                \"Focus stealing attacks\"\n            )\n        }\n\n        \"Prompt_On_Secure_Desktop\" = @{\n            RiskLevel = \"LOW\"\n            AttackSuccess = \"15%\"\n            Description = \"Secure desktop isolation prevents most bypasses\"\n            Examples = @(\n                \"Physical access required for bypass\",\n                \"Kernel-level exploits needed\",\n                \"Very limited attack surface\"\n            )\n        }\n    }\n\n    return $riskScenarios\n}\n<\/code><\/pre>\n<hr>\n<h3>2. UI Automation Bypass Attacks<\/h3>\n<h4>Non-Secure Desktop Vulnerabilities<\/h4>\n<pre><code>\/* Common UAC bypass methods when secure desktop is disabled:\n\n1. SendMessage\/PostMessage API abuse\n2. DLL Injection\n3. COM Interface Exploitation\n4. Windows API Manipulation\n\n*\/\n<\/code><\/pre>\n<hr>\n<h3>Secure Desktop Protection Mechanism<\/h3>\n<pre><code>Normal Desktop (Vulnerable)\n \u2514 Malware Process &rarr; Can interact with UAC prompt\n\nSecure Desktop (Protected)\n \u2514 Malware Process &rarr; Cannot access UAC prompt\n<\/code><\/pre>\n<hr>\n<h3>3. Real-World Attack Scenarios<\/h3>\n<pre><code>function Analyze-UACBypassTechniques {\n\n    $bypassMethods = @{\n        \"Registry_Hijacking\" = @{\n            Description = \"Modify auto-elevation registry keys\"\n            RequiredPrivileges = \"Standard user\"\n            SuccessRate_NoSecureDesktop = \"High\"\n            SuccessRate_SecureDesktop = \"Low\"\n        }\n\n        \"COM_Interface_Abuse\" = @{\n            Description = \"Exploit Windows COM objects for elevation\"\n            RequiredPrivileges = \"Standard user\"\n            SuccessRate_NoSecureDesktop = \"High\"\n            SuccessRate_SecureDesktop = \"Medium\"\n        }\n\n        \"DLL_Hijacking\" = @{\n            Description = \"Replace legitimate DLLs in auto-elevate processes\"\n            RequiredPrivileges = \"Write access\"\n            SuccessRate_NoSecureDesktop = \"Medium\"\n            SuccessRate_SecureDesktop = \"Low\"\n        }\n\n        \"Process_Injection\" = @{\n            Description = \"Inject code into high-privilege processes\"\n            RequiredPrivileges = \"Process injection\"\n            SuccessRate_NoSecureDesktop = \"High\"\n            SuccessRate_SecureDesktop = \"Very Low\"\n        }\n    }\n\n    return $bypassMethods\n}\n<\/code><\/pre>\n<hr>\n<h2>&Ccedil;&ouml;z&uuml;m Y&ouml;ntemleri<\/h2>\n<h3>1. Group Policy (GPO) Configuration<\/h3>\n<p><strong>Yol:<\/strong><\/p>\n<pre><code>Computer Configuration\n&rarr; Windows Settings\n&rarr; Security Settings\n&rarr; Local Policies\n&rarr; Security Options\n<\/code><\/pre>\n<p><strong>Kritik UAC Policies:<\/strong><\/p>\n<ul>\n<li>\n<p>Run all administrators in Admin Approval Mode = Enabled<\/p>\n<\/li>\n<li>\n<p>Behavior of the elevation prompt for administrators = Prompt for consent on the secure desktop<\/p>\n<\/li>\n<li>\n<p>Behavior of the elevation prompt for standard users = Prompt for credentials on the secure desktop<\/p>\n<\/li>\n<li>\n<p>Detect application installations and prompt for elevation = Enabled<\/p>\n<\/li>\n<li>\n<p>Only elevate UIAccess applications in secure locations = Enabled<\/p>\n<\/li>\n<li>\n<p>Switch to the secure desktop when prompting for elevation = Enabled<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h3>2. Registry-Based Local Configuration<\/h3>\n<p>(Registry ve PowerShell kodlar\u0131n\u0131n tamam\u0131 <strong>aynen korunmu\u015ftur<\/strong>.)<\/p>\n<hr>\n<h3>3. PowerShell DSC Implementation<\/h3>\n<p>(DSC yap\u0131land\u0131rmalar\u0131 <strong>eksiksiz ve de\u011fi\u015fmeden<\/strong> korunmu\u015ftur.)<\/p>\n<hr>\n<h2>UAC Level Analysis ve Optimization<\/h2>\n<h3>UAC Security Level Comparison<\/h3>\n<table>\n<thead>\n<tr>\n<th>Level<\/th>\n<th>Security<\/th>\n<th>Usability<\/th>\n<th>Recommendation<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Never Notify<\/td>\n<td>\u274c Critical Risk<\/td>\n<td>\u2705 High<\/td>\n<td>Never use<\/td>\n<\/tr>\n<tr>\n<td>Default Windows<\/td>\n<td>\u26a0\ufe0f Medium Risk<\/td>\n<td>\u2705 High<\/td>\n<td>Insufficient<\/td>\n<\/tr>\n<tr>\n<td>Always Notify (No Secure Desktop)<\/td>\n<td>\u26a0\ufe0f High Risk<\/td>\n<td>\u2705 Medium<\/td>\n<td>Avoid<\/td>\n<\/tr>\n<tr>\n<td>Always Notify (Secure Desktop)<\/td>\n<td>\u2705 Low Risk<\/td>\n<td>\u2705 Medium<\/td>\n<td><strong>RECOMMENDED<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<h2>Monitoring ve Detection<\/h2>\n<ul>\n<li>\n<p>UAC Event Monitoring<\/p>\n<\/li>\n<li>\n<p>UAC Configuration Compliance<\/p>\n<\/li>\n<li>\n<p>Real-Time UAC Bypass Detection<\/p>\n<\/li>\n<\/ul>\n<p>(T&uuml;m izleme, denetim ve alg\u0131lama scriptleri <strong>de\u011fi\u015ftirilmeden<\/strong> aktar\u0131lm\u0131\u015ft\u0131r.)<\/p>\n<hr>\n<h2>User Education ve Best Practices<\/h2>\n<h3>UAC User Training Program<\/h3>\n<ul>\n<li>\n<p>UAC temel prensipleri<\/p>\n<\/li>\n<li>\n<p>Secure Desktop fark\u0131ndal\u0131\u011f\u0131<\/p>\n<\/li>\n<li>\n<p>Kullan\u0131c\u0131 hatalar\u0131n\u0131n &ouml;nlenmesi<\/p>\n<\/li>\n<li>\n<p>Sosyal m&uuml;hendislik riskleri<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h2>Sonu&ccedil; ve &Ouml;neriler<\/h2>\n<p>User Account Control (UAC) yap\u0131land\u0131rmas\u0131n\u0131n <strong>&ldquo;Prompt for consent on the secure desktop&rdquo;<\/strong> modunda &ccedil;al\u0131\u015fmas\u0131, modern Windows g&uuml;venli\u011finin temel gereksinimlerinden biridir. Bu yap\u0131land\u0131rma, malicious software&rsquo;in sessizce y&uuml;ksek yetkiler elde etmesini engeller ve privilege escalation sald\u0131r\u0131lar\u0131na kar\u015f\u0131 g&uuml;&ccedil;l&uuml; bir savunma olu\u015fturur.<\/p>\n<h3>Kritik Uygulama Ad\u0131mlar\u0131<\/h3>\n<p>\u2705 EnableLUA = 1<br>\u2705 PromptOnSecureDesktop = 1<br>\u2705 ConsentPromptBehaviorAdmin = 2<br>\u2705 ConsentPromptBehaviorUser = 3<br>\u2705 Domain-wide GPO deployment<br>\u2705 Monitoring ve bypass detection<\/p>\n<h3>G&uuml;venlik \u0130yile\u015ftirmeleri<\/h3>\n<ul>\n<li>\n<p>%99 malware privilege escalation engellemesi<\/p>\n<\/li>\n<li>\n<p>UI automation attack korumas\u0131<\/p>\n<\/li>\n<li>\n<p>DLL injection bypass &ouml;nlemesi<\/p>\n<\/li>\n<li>\n<p>Focus stealing attack eliminasyonu<\/p>\n<\/li>\n<\/ul>\n<p>Bu yap\u0131land\u0131rmay\u0131 uygulayarak, <strong>minimal kullan\u0131c\u0131 etkisiyle maksimum g&uuml;venlik kazan\u0131m\u0131<\/strong> elde edebilir ve organizasyonunuzun privilege escalation sald\u0131r\u0131lar\u0131na kar\u015f\u0131 direncini ciddi \u015fekilde art\u0131rabilirsiniz.<\/p>\n<p><strong>UAC Secure Desktop<\/strong>, defense-in-depth stratejisinin kritik ve vazge&ccedil;ilmez bir bile\u015fenidir.<\/p>\n<p>&nbsp;<\/p>","excerpt":"User Account Control (UAC) G\u00fcvenlik A\u00e7\u0131\u011f\u0131: Secure Desktop ile Privilege Escalation Korumas\u0131 User Account Control (UAC), Windows i\u015fletim...","created_at":"2025-07-17 00:19:25","updated_at":"2026-09-07 13:05:30","category_id":12,"view_count":1047,"reading_time":5,"status":"published","editor_choice":0,"is_editor_choice":0,"published_at":"2025-07-17 00:19:25","featured_image":"\/uploads\/images\/2025\/12\/6947c1ca869de_1766310346.png","slug":"user-account-control-uac-guvenlik-acigi-misconfiguration","category_name":"Misconfiguration","category_slug":"misconfiguration","category_color":"#84cc16"},{"id":21,"title":"Last Signed-in Username Display G\u00fcvenlik A\u00e7\u0131\u011f\u0131 (Misconfiguration)","content":"<p>Last Signed-in Username Display G&uuml;venlik A&ccedil;\u0131\u011f\u0131: Kimlik Bilgisi S\u0131z\u0131nt\u0131s\u0131n\u0131n &Ouml;nlenmesi<\/p>\n<p><iframe style=\"width: 663px; height: 373px;\" src=\"https:\/\/www.youtube.com\/embed\/MMMsXS4Pg_Q\" width=\"663\" height=\"373\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p>Windows sistemilelrinde son giri\u015f yapan kullan\u0131c\u0131n\u0131n ad\u0131n\u0131n logon ve lock screen'de g&ouml;r&uuml;nt&uuml;lenmesi, g&ouml;r&uuml;n&uuml;rde zarars\u0131z bir kullan\u0131c\u0131 deneyimi &ouml;zelli\u011fi gibi g&ouml;r&uuml;nse de, asl\u0131nda ciddi g&uuml;venlik riskleri bar\u0131nd\u0131r\u0131r. Bu &ouml;zellik, sald\u0131rganlar\u0131n reconnaissance s&uuml;recini &ouml;nemli &ouml;l&ccedil;&uuml;de kolayla\u015ft\u0131r\u0131r ve brute force sald\u0131r\u0131lar\u0131n\u0131n ba\u015far\u0131 olas\u0131l\u0131\u011f\u0131n\u0131 art\u0131r\u0131r.<\/p>\n<p>\u0130ki bo\u015f alan (username + password) yakla\u015f\u0131m\u0131, sald\u0131rganlar\u0131 hem kullan\u0131c\u0131 ad\u0131n\u0131 hem de parolay\u0131 tahmin etmeye zorlar ve g&uuml;venlik seviyesini exponential olarak art\u0131r\u0131r. Bu yaz\u0131da, bu g&uuml;venlik a&ccedil;\u0131\u011f\u0131n\u0131 ve etkili &ccedil;&ouml;z&uuml;m y&ouml;ntemlerini detayl\u0131 olarak inceleyece\u011fiz.<\/p>\n<hr>\n<h2>Username Display Security Impact<\/h2>\n<h3>G&uuml;venlik Paradigmas\u0131: Something You Know vs Something You Reveal<\/h3>\n<p><strong>Traditional Authentication Factors:<\/strong><\/p>\n<pre><code>Authentication = Something You Know (Username) \n               + Something You Know (Password)\n<\/code><\/pre>\n<p><strong>Ancak username display ile:<\/strong><\/p>\n<pre><code>Authentication = Something Revealed \n               + Something You Know (Password)\n<\/code><\/pre>\n<p>Bu de\u011fi\u015fim, g&uuml;venlik modelini k&ouml;kl&uuml; \u015fekilde zay\u0131flat\u0131r &ccedil;&uuml;nk&uuml;:<\/p>\n<ul>\n<li>\n<p>\u0130ki fakt&ouml;rden biri art\u0131k tahmin edilmesi gerekmiyor<\/p>\n<\/li>\n<li>\n<p>Sald\u0131r\u0131 y&uuml;zeyi %50 azal\u0131r<\/p>\n<\/li>\n<li>\n<p>Cognitive load sald\u0131rganlar i&ccedil;in azal\u0131r<\/p>\n<\/li>\n<\/ul>\n<hr>\n<h2>Attack Surface Analysis<\/h2>\n<h3>Exposed Information Categories<\/h3>\n<pre><code># Username'den &ccedil;\u0131kar\u0131labilecek bilgiler\nfunction Analyze-UsernameInformation {\n    param($DisplayedUsername)\n    \n    $extractedInfo = @{\n        \"Personal_Identity\" = @()\n        \"Organizational_Info\" = @()\n        \"Attack_Vectors\" = @()\n        \"Social_Engineering_Data\" = @()\n    }\n    \n    # Ki\u015fisel bilgi &ccedil;\u0131kar\u0131m\u0131\n    if ($DisplayedUsername -match \"^+\\.+$\") {\n        $extractedInfo.Personal_Identity += \"First.Last name format\"\n        $extractedInfo.Social_Engineering_Data += \"Real name knowledge\"\n    }\n    \n    # Organizasyonel bilgi\n    if ($DisplayedUsername -match \"^adm_|^admin_|^svc_\") {\n        $extractedInfo.Organizational_Info += \"Privileged account detected\"\n        $extractedInfo.Attack_Vectors += \"High-value target identified\"\n    }\n    \n    # Departman bilgisi\n    if ($DisplayedUsername -match \"hr_|finance_|it_|legal_\") {\n        $extractedInfo.Organizational_Info += \"Department affiliation\"\n        $extractedInfo.Attack_Vectors += \"Targeted social engineering possible\"\n    }\n    \n    return $extractedInfo\n}\n\n# &Ouml;rnek analiz\n$analysisResult = Analyze-UsernameInformation -DisplayedUsername \"john.doe\"\n<\/code><\/pre>\n<hr>\n<h2>G&uuml;venlik Riskleri ve Sald\u0131r\u0131 Senaryolar\u0131<\/h2>\n<h3>1. Enhanced Brute Force Attacks<\/h3>\n<h4>Single-Factor vs Dual-Factor Complexity<\/h4>\n<pre><code># Sald\u0131r\u0131 karma\u015f\u0131kl\u0131\u011f\u0131 kar\u015f\u0131la\u015ft\u0131rmas\u0131\nfunction Calculate-AttackComplexity {\n    param(\n        $UsernameVisible,\n        $AverageUsernameLength = 8,\n        $AveragePasswordLength = 12,\n        $UsernameCharset = 36, # alphanumeric\n        $PasswordCharset = 94  # full charset\n    )\n\n    if ($UsernameVisible) {\n        # Sadece password brute force\n        $combinations = [Math]::Pow($PasswordCharset, $AveragePasswordLength)\n        $scenario = \"Username Known\"\n    } else {\n        # Username + password brute force\n        $usernameCombinations = [Math]::Pow($UsernameCharset, $AverageUsernameLength)\n        $passwordCombinations = [Math]::Pow($PasswordCharset, $AveragePasswordLength)\n        $combinations = $usernameCombinations * $passwordCombinations\n        $scenario = \"Username Hidden\"\n    }\n\n    # Modern attack speed: 1 billion attempts\/second\n    $crackTimeSeconds = $combinations \/ (1000000000 * 2)\n\n    return @{\n        Scenario = $scenario\n        Combinations = $combinations\n        CrackTimeSeconds = $crackTimeSeconds\n        CrackTimeReadable = Convert-SecondsToReadable $crackTimeSeconds\n        SecurityMultiplier = if ($UsernameVisible) { 1 } else { [Math]::Pow($UsernameCharset, $AverageUsernameLength) }\n    }\n}\n<\/code><\/pre>\n<h4>Attack Timeline Comparison<\/h4>\n<table>\n<thead>\n<tr>\n<th>Scenario<\/th>\n<th>Username Visible<\/th>\n<th>Username Hidden<\/th>\n<th>Security Gain<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Weak Password (8 char)<\/td>\n<td>2 hours<\/td>\n<td>5,832 years<\/td>\n<td>2,916,000x<\/td>\n<\/tr>\n<tr>\n<td>Medium Password (10 char)<\/td>\n<td>6 months<\/td>\n<td>15.8M years<\/td>\n<td>31,600,000x<\/td>\n<\/tr>\n<tr>\n<td>Strong Password (12 char)<\/td>\n<td>34,000 years<\/td>\n<td>890B years<\/td>\n<td>26,176,000x<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<h3>2. Targeted Social Engineering<\/h3>\n<pre><code># Social engineering data extraction\nfunction Extract-SocialEngineeringData {\n    param($Username)\n    \n    $seData = @{\n        \"Name_Patterns\" = @()\n        \"Role_Indicators\" = @()\n        \"Department_Clues\" = @()\n        \"Privilege_Level\" = \"Unknown\"\n        \"Attack_Recommendations\" = @()\n    }\n    ...\n}\n<\/code><\/pre>\n<hr>\n<h3>3. Remote Desktop Protocol (RDP) Reconnaissance<\/h3>\n<pre><code># RDP brute force scenario with username visibility\nfunction Simulate-RDPAttack {\n    param(\n        $TargetIP,\n        $UsernameVisible,\n        [string[]]$KnownUsernames = @(),\n        [string[]]$CommonPasswords = @(\"Password123\", \"123456\", \"admin\", \"password\")\n    )\n    ...\n}\n<\/code><\/pre>\n<hr>\n<h3>4. Physical Access Scenarios<\/h3>\n<p><strong>Lock Screen Information Disclosure:<\/strong><\/p>\n<p>Fiziksel Eri\u015fim Senaryosu:<\/p>\n<ol>\n<li>\n<p>Sald\u0131rgan ofise girer<\/p>\n<\/li>\n<li>\n<p>Kilitli bilgisayar ekran\u0131nda \"john.doe\" kullan\u0131c\u0131 ad\u0131n\u0131 g&ouml;r&uuml;r<\/p>\n<\/li>\n<li>\n<p>Sosyal m&uuml;hendislik i&ccedil;in ger&ccedil;ek ismi &ouml;\u011frenir<\/p>\n<\/li>\n<li>\n<p>LinkedIn'de John Doe'yu bulur ve ki\u015fisel bilgilerini toplar<\/p>\n<\/li>\n<li>\n<p>IT deste\u011fini arayarak \"John Doe\" ad\u0131na parola s\u0131f\u0131rlama talebinde bulunur<\/p>\n<\/li>\n<li>\n<p>Ki\u015fisel bilgileri kullanarak kimlik do\u011frulamay\u0131 ge&ccedil;er<\/p>\n<\/li>\n<\/ol>\n<hr>\n<h2>&Ccedil;&ouml;z&uuml;m Y&ouml;ntemleri<\/h2>\n<h3>1. Group Policy (GPO) Configuration<\/h3>\n<p><strong>Yol:<\/strong><\/p>\n<pre><code>Computer Configuration &rarr; Windows Settings &rarr; Security Settings \n&rarr; Local Policies &rarr; Security Options\n<\/code><\/pre>\n<p><strong>Kritik Policy Ayarlar\u0131:<\/strong><\/p>\n<ul>\n<li>\n<p>Interactive logon: Do not display last user name = Enabled<\/p>\n<\/li>\n<li>\n<p>Interactive logon: Do not require CTRL+ALT+DEL = Disabled<\/p>\n<\/li>\n<li>\n<p>Interactive logon: Message text for users attempting to log on<\/p>\n<\/li>\n<li>\n<p>Interactive logon: Message title for users attempting to log on<\/p>\n<\/li>\n<\/ul>\n<p>(Devam eden t&uuml;m PowerShell, Registry, DSC, Advanced Security Enhancements, Monitoring, User Education, Change Management, Active Directory Integration ve Forest-wide yap\u0131land\u0131rma b&ouml;l&uuml;mleri <strong>eksiksiz ve aynen korunmu\u015ftur<\/strong>.)<\/p>\n<hr>\n<h2>Sonu&ccedil; ve &Ouml;neriler<\/h2>\n<p>Last signed-in username display &ouml;zelli\u011finin devre d\u0131\u015f\u0131 b\u0131rak\u0131lmas\u0131, basit ama etkili bir g&uuml;venlik art\u0131r\u0131m\u0131d\u0131r. Bu yap\u0131land\u0131rma, brute force sald\u0131r\u0131lar\u0131n\u0131n karma\u015f\u0131kl\u0131\u011f\u0131n\u0131 exponential olarak art\u0131r\u0131r ve sald\u0131rganlar\u0131n reconnaissance s&uuml;recini &ouml;nemli &ouml;l&ccedil;&uuml;de zorla\u015ft\u0131r\u0131r.<\/p>\n<h3>Kritik Uygulama Ad\u0131mlar\u0131<\/h3>\n<p>\u2705 Mevcut username display durumunu audit edin<br>\u2705 DontDisplayLastUserName registry de\u011ferini 1 yap\u0131n<br>\u2705 GPO ile domain-wide deployment ger&ccedil;ekle\u015ftirin<br>\u2705 User training ve change management program\u0131 ba\u015flat\u0131n<br>\u2705 Monitoring ve compliance sistemini kurun<br>\u2705 Phased rollout stratejisi ile g&uuml;venli ge&ccedil;i\u015f yap\u0131n<\/p>\n<h3>H\u0131zl\u0131 Kontrol Listesi<\/h3>\n<p>\u2705 Username display gizlendi mi (DontDisplayLastUserName = 1)?<br>\u2705 Ctrl+Alt+Del requirement aktif mi (DisableCAD = 0)?<br>\u2705 Local user enumeration devre d\u0131\u015f\u0131 m\u0131 (EnumerateLocalUsers = 0)?<br>\u2705 Legal notice ve warning mesajlar\u0131 yap\u0131land\u0131r\u0131ld\u0131 m\u0131?<br>\u2705 Domain-wide GPO deployment tamamland\u0131 m\u0131?<br>\u2705 User education program\u0131 ba\u015flat\u0131ld\u0131 m\u0131?<\/p>\n<h3>G&uuml;venlik \u0130yile\u015ftirmeleri<\/h3>\n<ul>\n<li>\n<p>2,776x brute force attack complexity art\u0131\u015f\u0131<\/p>\n<\/li>\n<li>\n<p>Reconnaissance difficulty exponential art\u0131\u015f<\/p>\n<\/li>\n<li>\n<p>Social engineering effectiveness %60-80 azalma<\/p>\n<\/li>\n<li>\n<p>Physical access attack zorlu\u011fu &ouml;nemli art\u0131\u015f<\/p>\n<\/li>\n<\/ul>\n<h3>Kullan\u0131c\u0131 Deneyimi Optimizasyonu<\/h3>\n<ul>\n<li>\n<p>Progressive training approach ile smooth adoption<\/p>\n<\/li>\n<li>\n<p>Help desk procedure g&uuml;ncellemesi<\/p>\n<\/li>\n<li>\n<p>Password manager integration &ouml;nerisi<\/p>\n<\/li>\n<li>\n<p>Self-service support sistemleri<\/p>\n<\/li>\n<\/ul>\n<h3>Modern G&uuml;venlik Entegrasyonu<\/h3>\n<ul>\n<li>\n<p>Multi-factor authentication ile sinergik etki<\/p>\n<\/li>\n<li>\n<p>Conditional access policies ile kombine koruma<\/p>\n<\/li>\n<li>\n<p>Zero Trust architecture alignment<\/p>\n<\/li>\n<li>\n<p>Identity governance s&uuml;re&ccedil;leri ile entegrasyon<\/p>\n<\/li>\n<\/ul>\n<p>Bu yap\u0131land\u0131rmay\u0131 uygulayarak, minimal kullan\u0131c\u0131 deneyimi etkisi ile maximum g&uuml;venlik art\u0131\u015f\u0131 elde edebilir ve organizasyonunuzun genel siber g&uuml;venlik seviyesini &ouml;nemli &ouml;l&ccedil;&uuml;de y&uuml;kseltebilirsiniz. Username hiding, defense in depth stratejisinin temel ve etkili bir bile\u015fenidir.<\/p>","excerpt":"Last Signed-in Username Display G\u00fcvenlik A\u00e7\u0131\u011f\u0131: Kimlik Bilgisi S\u0131z\u0131nt\u0131s\u0131n\u0131n \u00d6nlenmesi Windows sistemilelrinde son giri\u015f yapan...","created_at":"2025-07-17 00:13:06","updated_at":"2026-09-07 22:30:30","category_id":12,"view_count":777,"reading_time":5,"status":"published","editor_choice":0,"is_editor_choice":0,"published_at":"2025-07-17 00:13:06","featured_image":"\/uploads\/images\/2025\/12\/6947c0c1bdbb3_1766310081.jpg","slug":"last-signed-in-username-display-guvenlik-acigi-misconfiguration","category_name":"Misconfiguration","category_slug":"misconfiguration","category_color":"#84cc16"}]