Offensive JA3 – Max Harley (SO-CON 2020)
Автор: SpecterOps
Загружено: 2020-12-17
Просмотров: 3637
Описание:
JA3 is a method for fingerprinting TLS clients using encryption options in the TLS ClientHello packet. Theoretically, this method of detecting malicious traffic is marginally better than the User-Agent header in HTTP since the client is in control of the ClientHello packet. Currently, there is little tooling available to easily craft ClientHello packets, so the JA3 hash is, practically, a great detection mechanism. This talk will discuss how the ja3transport project was created to fix the problem of unmodifiable JA3 signatures for red teamer, and how JA3 can also be used for keying payloads and keying C2 proxy traffic. We will also discuss how Satellite enables red team operators to easily key their payloads with associated network traffic, and one of the keying options Satellite implements is JA3. We'll describe how, combined with the ja3transport tool, Satellite allows operators to have a custom JA3 signature which is keyed to the redirector for proxying.
Contact
Twitter: / 0xdab0
Slack: https://bloodhoundgang.herokuapp.com
References
JA3: https://github.com/salesforce/ja3
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: