DEF CON 29 - Jacob Baines - Bring Your Own Print Driver Vulnerability

  Рет қаралды 6,094

DEFCONConference

DEFCONConference

Күн бұрын

What can you do, as an attacker, when you find yourself as a low privileged Windows user with no path to SYSTEM? Install a vulnerable print driver! In this talk, you'll learn how to introduce vulnerable print drivers to a fully patched system. Then, using three examples, you'll learn how to use the vulnerable drivers to escalate to SYSTEM.
REFERENCES:
Yarden Shafir and Alex Ionescu, PrintDemon: Print Spooler Privilege Escalation, Persistence & Stealth (CVE-2020-1048 & more) - windows-intern...
voidsec, CVE-2020-1337 - PrintDemon is dead, long live PrintDemon! - voidsec.com/cv...
Zhipeng Huo and Chuanda Ding, Evil Printer: How to Hack Windows Machines with Printing Protocol - media.defcon.o... CON 28/DEF CON Safe Mode presentations/DEF CON Safe Mode - Zhipeng-Huo and Chuanda-Ding - Evil Printer How to Hack Windows Machines with Printing Protocol.pdf
Pentagrid AG, Local Privilege Escalation in many Ricoh Printer Drivers for Windows (CVE-2019-19363) - www.pentagrid....
space-r7, Add module for CVE-2019-19363 - github.com/rap...
Microsoft, Point and Print with Packages - docs.microsoft...
Microsoft, Driver Store - docs.microsoft...
Microsoft, Printer INF Files - docs.microsoft...
Microsoft, Use Group Policy settings to control printers in Active Directory - docs.microsoft...

Пікірлер: 4
@vwspeedracer
@vwspeedracer 3 жыл бұрын
Are we just gonna say 2020-1337 and move along like it's not hilarious?
@jmr
@jmr 3 жыл бұрын
Nice work.
@kevinbissinger
@kevinbissinger 3 жыл бұрын
I'm a comment!
Minecraft Creeper Family is back! #minecraft #funny #memes
00:26
Man Mocks Wife's Exercise Routine, Faces Embarrassment at Work #shorts
00:32
Fabiosa Best Lifehacks
Рет қаралды 6 МЛН
小天使和小丑太会演了!#小丑#天使#家庭#搞笑
00:25
家庭搞笑日记
Рет қаралды 40 МЛН
DEF CON 29 - Richard Henderson - Old MacDonald Had a Barcode, E I E I CAR
43:40
DEF CON 29 - Thomas Roth - Hacking the Apple AirTags
38:31
DEFCONConference
Рет қаралды 29 М.
HackTheBox - Driver
40:01
IppSec
Рет қаралды 43 М.
CrowdStrike IT Outage Explained by a Windows Developer
13:40
Dave's Garage
Рет қаралды 2,1 МЛН
Minecraft Creeper Family is back! #minecraft #funny #memes
00:26