No video

"Bringing Harmony to IIS: Using game mods to protect (or nuke) your web server", Adrian Justice

  Рет қаралды 176

BSides Canberra

BSides Canberra

Күн бұрын

With an ever increasing number of developers using .NET based game engines, game modders have developed sophisticated tools which can interact with the .NET Common Language Runtime to modify game mechanics, add features and fundamentally modify how games operate at runtime.
But what's stopping us from using these tools to mess with other .NET based applications? Say...an IIS web server running Microsoft Exchange?
Absolutely Nothing!
Join me as I deploy Harmony, a popular .NET method hooking library, onto a Microsoft IIS server inorder to access (and tamper with) method parameters, return values and functionality.
I'll demonstrate several methods to load Harmony into IIS before looking at the level of control Harmony gives us over various interesting methods regular web applications utilise.
Next I'll explore some defensive uses for method hooking including logging method parameters sent to commonly abused functions, preventing method calls, and messing with adversaries by tampering with outputs.
I'll also cover some offensive uses for method hooking such as password logging and persistence.
Adrian Justice
Adrian (@zeroedtech) is threat hunter specialising in IIS, webshells and .NET, with a little bit of software development thrown in.

Пікірлер
Publish .NET 5 Web API on IIS || .NET Core Hosting on IIS
6:37
AshProgHelp - Programming Help
Рет қаралды 53 М.
طردت النملة من المنزل😡 ماذا فعل؟🥲
00:25
Cool Tool SHORTS Arabic
Рет қаралды 24 МЛН
Incredible Dog Rescues Kittens from Bus - Inspiring Story #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 29 МЛН
Happy birthday to you by Tsuriki Show
00:12
Tsuriki Show
Рет қаралды 12 МЛН
SSH Crash Course | With Some DevOps
55:02
Traversy Media
Рет қаралды 551 М.
Programming's Greatest Mistakes • Mark Rendle • GOTO 2023
51:24
GOTO Conferences
Рет қаралды 90 М.
Neon: Serverless Cloud SQL
59:00
Coding with Callie
Рет қаралды 113
SSH and Web Server Project PLD - ALX
2:52:51
Dr. Ehoneah Obed
Рет қаралды 14 М.
What is a Server? (Deepdive)
17:51
LiveOverflow
Рет қаралды 176 М.
Learn Web Development And ACTUALLY Get A Job | Ultimate Guide
1:33:52
James Cross
Рет қаралды 1,3 МЛН
طردت النملة من المنزل😡 ماذا فعل؟🥲
00:25
Cool Tool SHORTS Arabic
Рет қаралды 24 МЛН