Myvideo

Guest

Login

Searching for RPC Functions to Coerce Authentications in Microsoft Protocols

Uploaded By: Myvideo
1 view
0
0 votes
0

...In this talk, we’ll explore a way to automate this process by parsing Microsoft’s OpenSpecs online documentation as well as Interface Definition Language code. After that, we’ll use the gathered data to automatically find RPC calls potentially triggering authentications and generate python proof of concept code to trigger them remotely. Using this method, we find existing PrinterBug, PetitPotam, ShadowCoerce and DFSCoerce vulnerabilities in a matter of minutes.... By: Remi Gascou (Podalirius) Full Abstract and Presentation Materials: #searching-for-rpc-functions-to-coerce-authentications-in-microsoft-protocols-29154

Share with your friends

Link:

Embed:

Video Size:

Custom size:

x

Add to Playlist:

Favorites
My Playlist
Watch Later