Go offline with the Player FM app!
Meterpreter with Categorized Domains & Trusted Certs - Tradecraft Security Weekly #4
Manage episode 272907328 series 2794644
It is common for organizations to proxy web traffic so they can place restrictions on what websites can be visited by employees. To make the management of allowing or denying access to a large number of sites easier many web proxies utilize categorization engines to group sites into various subjects. Uncategorized sites are generally blocked. In this episode I show how it's easy to locate recently expired domains that have been categorized already, and can be utilized to get past web proxy filters. Additionally, I show how easy it is to set up a trusted certificate on the payload handler to encrypt the session using a custom cert.
Links: DomainHunter - https://github.com/minisllc/domainhunter
Brian Fehrman Blog Post - http://www.blackhillsinfosec.com/?p=5831
14 episodes
Manage episode 272907328 series 2794644
It is common for organizations to proxy web traffic so they can place restrictions on what websites can be visited by employees. To make the management of allowing or denying access to a large number of sites easier many web proxies utilize categorization engines to group sites into various subjects. Uncategorized sites are generally blocked. In this episode I show how it's easy to locate recently expired domains that have been categorized already, and can be utilized to get past web proxy filters. Additionally, I show how easy it is to set up a trusted certificate on the payload handler to encrypt the session using a custom cert.
Links: DomainHunter - https://github.com/minisllc/domainhunter
Brian Fehrman Blog Post - http://www.blackhillsinfosec.com/?p=5831
14 episodes
Tất cả các tập
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.