ZA·034 Tool 2016

SensePost XRDP Tool

Event
BSides Cape Town
Region
South Africa
Language
EN

Abstract

In this talk, we'll cover how an X server functions, how one becomes vulnerable, previous methods of exploitation, and finally the developed tool as well as how it works and what it provides. In 1997, a vulnerability in X11 was released that allowed unauthenticated access to the X server due to access controls being disabled [1]. This vulnerability gives an attacker full control of the target host using the default X toolset developed to work using the protocol. Given the age of this vulnerability, it is still being found while on internal penetration tests and even on the Internet.