ZA·034 Tool 2016
SensePost XRDP Tool
- Event
- BSides Cape Town
- Region
- South Africa
- Language
- EN
Abstract
In this talk, we'll cover how an X server functions, how one becomes vulnerable, previous methods of exploitation, and finally the developed tool as well as how it works and what it provides. In 1997, a vulnerability in X11 was released that allowed unauthenticated access to the X server due to access controls being disabled [1]. This vulnerability gives an attacker full control of the target host using the default X toolset developed to work using the protocol. Given the age of this vulnerability, it is still being found while on internal penetration tests and even on the Internet.
Sources
- Watch the recording youtube.com
- Where this entry came from bsidescapetown.co.za
No archived mirror recorded yet. Regional conference sites go dark often — adding a Wayback link keeps this entry usable.
Source of truth:
data/works/sensepost-xrdp-tool-2016.yaml