Series
esc17-beyond-wsus
Every article in the "esc17-beyond-wsus" series, in reading order.
4 posts · 80 min read in total
- ESC17 - Beyond WSUS: Introduction and Threat ModelESC17 is not a WSUS bug but a PKI trust problem in ADCS. The first part of a research series that maps out its attack surface. · 10 min read
- ESC17 - Beyond WSUS: Intercepting Internal HTTPSESC17 forges a domain-trusted certificate. Against internal HTTPS, it surfaces credentials, session tokens, and Windows authentications in the clear. · 25 min read
- ESC17 - Beyond WSUS: Hijacking Kerberos Sessions over LDAPSESC17 breaks LDAPS TLS, but authentication lives above it: cleartext bind capture and session hijacking, against NTLM as well as Kerberos, on the DC. · 28 min read
- ESC17 - Beyond WSUS: RDP Interception and NLA BypassESC17 removes the RDP certificate warning. NLA downgrade no longer works against a modern client, but terminating CredSSP captures the password despite NLA. · 17 min read