Skip to main content

Series

esc17-beyond-wsus

Every article in the "esc17-beyond-wsus" series, in reading order.

4 posts · 80 min read in total

  1. ESC17 - Beyond WSUS: Introduction and Threat ModelESC17 is not a WSUS bug but a PKI trust problem in ADCS. The first part of a research series that maps out its attack surface. · 10 min read
  2. ESC17 - Beyond WSUS: Intercepting Internal HTTPSESC17 forges a domain-trusted certificate. Against internal HTTPS, it surfaces credentials, session tokens, and Windows authentications in the clear. · 25 min read
  3. ESC17 - Beyond WSUS: Hijacking Kerberos Sessions over LDAPSESC17 breaks LDAPS TLS, but authentication lives above it: cleartext bind capture and session hijacking, against NTLM as well as Kerberos, on the DC. · 28 min read
  4. ESC17 - Beyond WSUS: RDP Interception and NLA BypassESC17 removes the RDP certificate warning. NLA downgrade no longer works against a modern client, but terminating CredSSP captures the password despite NLA. · 17 min read

All posts

Actions

Switch languageOpen the RSS feed

Go to

HomeBlogTagsArchives