Owning One to Rule Them All

No ratings

Presented at DEF CON 20 by

As penetration testers, we often try to impact an organization as efficient and effective as we can to simulate an attack on an organization. What if you could own one system to own them all? Thats it, one system. Its all you need, its in every company, and as soon as you compromise it, the rest fall (no not a domain controller). This presentation will cover a recent penetration test where I came up with a unique avenue to getting over 13,000 shells in just a few minutes by popping one server. Ill be releasing some custom tools to make this simplistic and automate the majority of what was used on this attack. Lets pop a box.