Asia-24-Shi-A-Glimpse-Into-The-Protocol.pdf

编号:161168 PDF 52页 4.87MB 下载积分:VIP专享
下载报告请您先登录!

Asia-24-Shi-A-Glimpse-Into-The-Protocol.pdf

1、#BHASIA BlackHatEventsA Glimpse Into The ProtocolFuzz Windows RDP Client For Fun And ProfitYingqi Shi(Mas0nShi),Mingjia Liu(cyberestro),Quan Jin(jq0904)DBAPPSecurity#BHASIA BlackHatEventsAbout UsYingqi ShiMas0nShiMingjia LiucyberestroQuan Jinjq0904Guoxian Zhong_p01arisZSiyuan Liu4nsw3r123#BHASIA Bla

2、ckHatEventsAgendaMotivationIntroductionFuzzingCase StudyFuture#BHASIA BlackHatEventsMotivation#BHASIA BlackHatEventsMotivation Popular Remote Access Solution Legacy and Longevity And more?https:/www.shodan.io/search?query=port%3A%223389%22#BHASIA BlackHatEventsMotivation Few vulnerabilities in RDP i

3、n the past year(01/2022-09/2023)https:/ BlackHatEventsIntroduction#BHASIA BlackHatEventsRDP Overview RDP contains the following features Clipboard Printer Storage Device Smart Card Audio IN/OUT#BHASIA BlackHatEventsRDP Client Attack Victims connect malicious server using mstsc.exe#BHASIA BlackHatEve

4、ntsRDP Server Attack Attackers take control of the RDP Server using mstsc.exe#BHASIA BlackHatEventsClient or Server?#BHASIA BlackHatEventsFocus on Microsoft RDP Client Why MS RDP Client?Clarity(mstscax.dll,etc.)Operability(Public APIs)Simplicity(Compared to RDP Server)Quickly(Learn from previous wor

5、ks)#BHASIA BlackHatEventsPrevious Works#BHASIA BlackHatEventsRDP Virtual Channel Virtual Channel Static Virtual Channel Dynamic Virtual Channelhttps:/ BlackHatEventsRDP Virtual Channel#BHASIA BlackHatEventsRDP Virtual ChannelRDPSNDRDPDRTSMF#BHASIA BlackHatEventsVirtual Channel API WTS API Open Serve

6、r Open Virtual Channel Write/Read Virtual Channel Close Virtual Channel Close Server https:/ BlackHatEventsFuzzing#BHASIA BlackHatEventsOpen Source RDP Fuzzerrdpfuzzhttps:/ BlackHatEventsFuzzing Architecture#1https:/ Loop#BHASIA BlackHatEventsFuzzing Architecture#2 Proxyhttps:/ BlackHatEventsChoose

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(Asia-24-Shi-A-Glimpse-Into-The-Protocol.pdf)为本站 (张5G) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠