Главная
Study mode:
on
1
Intro
2
Who is Ryan
3
Agenda
4
Certificate Signing
5
Trust Architecture
6
Microsoft Quote
7
Why Did I Use ClickOnce
8
Powershell
9
Veil Evasion
10
Bail
11
Foot Bones
12
Server Setup
13
Command and Control
14
Cleanup
15
Demo
16
Visual Studio
17
Code
18
Target Framework
19
Full Trust Application
20
Application Files
21
Publishing Files
22
Hero
23
Login Page
24
Invalid Password
25
Security Prompt
26
Unknown Publisher
27
Run App
28
Preventive Measures
29
Registry Settings
30
Smart Screen
31
Smart Screen Flow Chart
32
Why Use Science Executable
Description:
Explore the security implications of ClickOnce deployment technology in this AppSec California 2016 conference talk. Discover how ClickOnce, a fast and easy software deployment solution, can be exploited by malicious actors to gain a foothold in networks. Learn about a new methodology combining ClickOnce technology with phishing techniques to establish an initial presence in an environment with minimal user interaction. Gain insights into the "one click" approach that allows attackers to pivot and escalate their access. Delve into topics such as certificate signing, trust architecture, PowerShell, Veil evasion, and command and control setup. Watch a live demo showcasing the creation of a malicious ClickOnce application using Visual Studio, and understand preventive measures like registry settings and Smart Screen. This 40-minute presentation by Ryan Gandrud, a senior security consultant at NetSPI, offers valuable knowledge for cybersecurity professionals and IT administrators concerned with secure software deployment. Read more

ClickOnce Exploitation: One-Click Network Foothold - AppSec California 2016

OWASP Foundation
Add to list
0:00 / 0:00