DEF CON 26 - William Martin - SMBetray Backdooring and Breaking Signatures
1,251 views · Published 22 October 2018 · 37:33 · Indexed 6 October 2026
Channel: DEFCONConference · 2018 · Science & Technology
When it comes to taking advantage of SMB connections, most tools available to penetration testers aim for system enumeration or for performing relay attacks to gain RCE. If signatures are required, or if the victims relayed are not local admins anywhere, that can put a real stint in leveraging SMB to gain any serious footholds in a network. Fortunately, the mentioned attacks are only the tip of the iceberg of the ways to gain RCE with insecure SMB connections – and there’s a new tool to help take full advantage of these opportunities.
More from this channel
-
7:53
DEF CON 20 Documentary Bonus Clips - CDC muxed
-
3:45
DEF CON 20 Documentary Bonus Clips - Not the Same Anymore
-
2:39
DEF CON 20 Documentary Bonus Clips - Barkode and Bloodkode
-
47:43
DEF CON 20 - Raphael Mudge - Cortana: Rise of the Automated Red Team
-
43:15
DEF CON 20 - Peter Hannay - Exchanging Demands
-
49:37
DEF CON 20 - Richard Thieme - Twenty Years Back Twenty Years Ahead
-
25:01
DEF CON 20 - Ryan Holeman - Passive Bluetooth Monitoring in Scapy
-
48:14
DEF CON 20 - Xeno Kovah and Corey Kallenberg - No More Hooks