Searching for RPC Functions to Coerce Authentications in Microsoft Protocols
Автор: Black Hat
Загружено: 2023-03-31
Просмотров: 1138
Описание:
...In this talk, we'll explore a way to automate this process by parsing Microsoft's OpenSpecs online documentation as well as Interface Definition Language code. After that, we'll use the gathered data to automatically find RPC calls potentially triggering authentications and generate python proof of concept code to trigger them remotely. Using this method, we find existing PrinterBug, PetitPotam, ShadowCoerce and DFSCoerce vulnerabilities in a matter of minutes....
By: Remi Gascou (Podalirius)
Full Abstract and Presentation Materials:
https://www.blackhat.com/eu-22/briefi...
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: