Top 10 winner
Infiltrating Corporate Intranet Like NSA: Pre-Auth RCE On Leading SSL VPNs
Orange Tsai - Infiltrating Corporate Intranet Like NSA Preauth RCE - DEF CON 27 Conference
Pre-auth remote code execution chains against Fortigate and Pulse Secure SSL VPNs: traversal file reads, a heap overflow in the web proxy, an undocumented password-reset key, and command injection through a flaw in Pulse's Perl I/O redirection guard. Stolen session databases defeat two-factor auth, and the logon-script feature turns the VPN into a way to compromise every connected client.
Record
- Document
- Orange Tsai - Infiltrating Corporate Intranet Like NSA Preauth RCE - DEF CON 27 Conference
- Researcher
- Orange Tsai and Meh Chang
- Published by
- HITCON
- Date
- Format
- Recording
- Topic
- Server
In the archive
Related sources
- Infiltrating Corporate Intranet Like NSA: Pre-auth RCE on Leading SSL VPNs Slides
- HITCON CMT 2019 - Infiltrating Corporate Intranet Like NSA - Pre-auth RCE on Leading SSL VPNs
Tags
This page is the archive's own catalogue record. The research is the work of Orange Tsai and Meh Chang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .