ChaMd5 Team 00后登上国际安全顶会BlackHat!
日前,全球顶尖安全技术会议BlackHat Asia在新加坡召开,ChaMd5 Team成员zhefox受邀参会并作主题演讲。
议题介绍
《A Glimpse Into The Protocol: Fuzz Windows RDP Client For Fun And Profit》
At the end of June 2023, we decided to conduct vulnerability research on the Windows RDP client. Initially, we read some publicly available blogs and modified two open-source Windows RDP fuzzing projects. During this process, we successfully identified an old Windows RDP client vulnerability but did not discover any new vulnerabilities.
Just when we were hesitating, we studied Yuki Chen's presentation slides at Blackhat USA 2023. Subsequently, we decided to incorporate race conditions into the vulnerability research of the Windows RDP protocol, leading us to eventually uncover several remote code execution vulnerabilities in Windows RDP client.
This presentation will share the entire process of our Windows RDP client vulnerability research: why we chose Windows RDP as the target, how we collect public information to initiate research, how we modified open-source fuzzing tools to improve them, and how we overcame challenges to discover several remote code execution vulnerabilities in Windows RDP clients. We will also share details of the discovered Windows RDP client vulnerabilities.
At the end of this presentation, we will integrate the experiences mentioned above and give some recommendations for Windows RDP vulnerability defence.
目前,该议题的演讲PPT已经在BlackHat官网公开,有兴趣的读者请点击文末“阅读原文”了解更多精彩内容。
- END -
关注公众号:拾黑(shiheibook)了解更多
[广告]赞助链接:
四季很好,只要有你,文娱排行榜:https://www.yaopaiming.com/
让资讯触达的更精准有趣:https://www.0xu.cn/
关注网络尖刀微信公众号
随时掌握互联网精彩
随时掌握互联网精彩
赞助链接
排名
热点
搜索指数
- 1 习近平拉美之行的三个“一” 7951156
- 2 微信或史诗级“瘦身” 内存有救了 7918930
- 3 男子求助如何打开亡父遗留14年手机 7844503
- 4 中国主张成为G20峰会的一抹亮色 7792490
- 5 中国对日本等国试行免签 7667174
- 6 7万余件儿童羽绒服里没有真羽绒 7593952
- 7 女生半裸遭男保洁刷卡闯入 酒店回应 7447125
- 8 70多辆小米SU7同一天撞墙撞柱 7390217
- 9 操纵股价 2人被证监会罚没近3.35亿 7210323
- 10 千年古镇“因网而变、因数而兴” 7178377