当前位置:首页 > 报告详情

Asia-24-Shi-A-Glimpse-Into-The-Protocol.pdf

上传人: 张** 编号:161168 2024-05-05 52页 4.87MB

1、#BHASIA BlackHatEventsA Glimpse Into The ProtocolFuzz Windows RDP Client For Fun And ProfitYingqi Shi(Mas0nShi),Mingjia Liu(cyberestro),Quan Jin(jq0904)DBAPPSecurity#BHASIA BlackHatEventsAbout UsYingqi ShiMas0nShiMingjia LiucyberestroQuan Jinjq0904Guoxian Zhong_p01arisZSiyuan Liu4nsw3r123#BHASIA Bla

2、ckHatEventsAgendaMotivationIntroductionFuzzingCase StudyFuture#BHASIA BlackHatEventsMotivation#BHASIA BlackHatEventsMotivation Popular Remote Access Solution Legacy and Longevity And more?https:/www.shodan.io/search?query=port%3A%223389%22#BHASIA BlackHatEventsMotivation Few vulnerabilities in RDP i

3、n the past year(01/2022-09/2023)https:/ BlackHatEventsIntroduction#BHASIA BlackHatEventsRDP Overview RDP contains the following features Clipboard Printer Storage Device Smart Card Audio IN/OUT#BHASIA BlackHatEventsRDP Client Attack Victims connect malicious server using mstsc.exe#BHASIA BlackHatEve

4、ntsRDP Server Attack Attackers take control of the RDP Server using mstsc.exe#BHASIA BlackHatEventsClient or Server?#BHASIA BlackHatEventsFocus on Microsoft RDP Client Why MS RDP Client?Clarity(mstscax.dll,etc.)Operability(Public APIs)Simplicity(Compared to RDP Server)Quickly(Learn from previous wor

5、ks)#BHASIA BlackHatEventsPrevious Works#BHASIA BlackHatEventsRDP Virtual Channel Virtual Channel Static Virtual Channel Dynamic Virtual Channelhttps:/ BlackHatEventsRDP Virtual Channel#BHASIA BlackHatEventsRDP Virtual ChannelRDPSNDRDPDRTSMF#BHASIA BlackHatEventsVirtual Channel API WTS API Open Serve

6、r Open Virtual Channel Write/Read Virtual Channel Close Virtual Channel Close Server https:/ BlackHatEventsFuzzing#BHASIA BlackHatEventsOpen Source RDP Fuzzerrdpfuzzhttps:/ BlackHatEventsFuzzing Architecture#1https:/ Loop#BHASIA BlackHatEventsFuzzing Architecture#2 Proxyhttps:/ BlackHatEventsChoose

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要介绍了针对Windows远程桌面协议(RDP)客户端的模糊测试研究,重点是Microsoft RDP客户端。作者们开发了一种新的模糊器,并在几天内找到了一些新的崩溃。文章详细分析了RDP客户端的攻击方式,包括客户端和服务器攻击,以及为何选择MS RDP客户端作为研究对象。文章还提到了之前的工作,包括对RDP虚拟通道的模糊测试,以及如何通过移植honggfuzz的变异策略和覆盖可视化来增强模糊器。最后,文章分享了一些未来的研究方向,包括更多的RDP服务器通道和协议,并感谢了参与研究和参考文献。
"Windows RDP Client安全吗?" "如何利用RDP虚拟通道进行攻击?" "如何有效地对Windows RDP进行模糊测试?"
客服
商务合作
小程序
服务号
折叠