当前位置:首页 > 报告详情

The ever-present specter in memory-A Post Exploitation Toolkit for High Value Systems.pdf

上传人: 张** 编号:174253 2024-09-01 32页 8.92MB

1、演讲人:Skay时间:2024.08.25PART ONE01MANDAMUS MEDIOCREM REREHENDUNT漏洞价值最大化全面、长期、隐蔽高价值Web应用后渗透high-value web applicationsdomain management team buildingdefect tracking platforms,documents code repository management platformsApplication-orientedMANT EUM EList applicationsList applicationsList applicationsLi

2、st applicationsMANT EUM E初始权限初始权限获取初始权限PART ONE02Post-Exploitation Post-Exploitation F Functions unctions List applicationsMANT EUM E为了提高后门的隐蔽性,采用无需落地的内存Shell,针对重启失效问题,可以采用agent形式,但是与其新增一个落地jar文件,不如修改已有文件。当然还需修改文件修改时间zimbra本身功能上支持插件扩展,且默认安装以下常用插件持久性后门隐藏MANT EUM EMemory-ShellMANT EUM EObtain the desi

3、red DATAObtain the desired DATAMANT EUM ENo,we have a better wayNo,we have a better wayhttps:/ the python-zimbra library.Offer functionality to handle the creation of Zimbra SOAP queries.Send HTTP requests to the backend for processing.Retrieve desired data by calling SOAP API through HTTP requests.

4、Is it really necessary to make such a fuss about it?DebugDebugObtain the desired DATAObtain the desired DATADebugDebug从层紧密嵌套的调用栈数据库连接数据库连接Obtain the desired DATADatabase Connection InformationObtain the desired DATAObtain the desired DATAUser list and details retrieval分析认证机制分析认证机制Obtain the desired

5、DATAObtain the desired DATA Generate arbitrary user login credentials凭证伪造凭证伪造会话劫持会话劫持try to construct OperationContext,SearchParams,Mailbox,etc.Among themObtain the desired DATAObtain the desired DATAObtain the desired DATAObtain the desired DATAMail information retrievaDebugDebugObtain the desired

6、DATAObtain the desired DATAMail information retrievaDebugDebugDebugDebug流量侧隐蔽流量侧隐蔽Mail information retrievaPART ONE021obtaining domain controller administrator information and database-stored domain information,2obtaining database connection information,3obtaining integrated thir

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
Skay在2024年8月25日的演讲中,主要讨论了高价值Web应用后渗透技术。他详细阐述了如何最大化漏洞价值,并实现全面、长期、隐蔽的渗透。关键点包括: 1. 采用内存Shell提高后门隐蔽性,并通过修改已有文件而非新增jar文件来解决重启失效问题。 2. 利用Zimbra的SOAP API,通过HTTP请求获取所需数据,避免直接落地。 3. 分析Zoho ADManager Plus,提取数据库连接信息、域控制器凭据、数据库存储的域名信息等。 4. 生成最高权限账户的有效登录信息,绕过IP登录限制,并记录明文密码。 5. 通过修改ADManager的启动行为,实现持久化后门留存。 Skay的演讲为高价值Web应用后利用工具的开发提供了思路。他的研究涵盖多个后利用功能,包括持久性、隐蔽性和数据窃取,展示了渗透测试的复杂性和深入性。
"高价值Web应用后渗透技术探讨" "如何实现Web应用后门的隐蔽性和持久化" "深入解析Zoho等第三方应用的认证机制与安全漏洞"
客服
商务合作
小程序
服务号
折叠